2025 GrayRobinson - unauthorized network access exposed PII and PHI for 65,113 individuals
Data compromised
Names, dates of birth, SSNs, driver license numbers, state/government IDs, financial account information, medical information, and health insurance information
Technical writeup
GrayRobinson disclosed that unauthorized actors may have accessed or removed files from its systems during a window from March 5 through March 24, 2025. The firm determined on April 13, 2026 that impacted files may have contained personal information and began notifications on April 24, 2026. State notices and summaries placed the affected population at approximately 65,113 individuals.
Root cause
Unauthorized access to law-firm network and potential file removal