2025 Tarter Krinsky & Drogin — external breach exposed client and personal data (disclosed June 2026)
Data compromised
Names, SSNs, driver’s licenses, DOB, passports, tax IDs, financial and payment card data, credentials, medical and health insurance info, biometrics (varies by individual)
Technical writeup
New York law firm Tarter Krinsky & Drogin LLP confirmed a data security event after detecting suspicious activity September 10, 2025. Forensics found unauthorized access to certain servers between July 9 and September 9, 2025, with files viewed or obtained by an external actor. TKD’s June 2026 website notice and Maine Attorney General filing describe attorney-client privileged material plus personal identifiers including SSNs, financial data, medical information, and biometrics for affected individuals. Consumer letters went out June 5, 2026, with 12 months of TransUnion credit monitoring; an aggregate victim count had not been published at catalog time.
Root cause
External system breach (hacking); unauthorized server access July 9–September 9, 2025