Seyfarth Shaw Data Breach Investigation

Regulatory records report a data security incident involving Seyfarth Shaw LLP, a legal services firm, and indicate that names and Social Security numbers may have been involved. The reported incident may create risks of identity theft, targeted phishing, and professional-services impersonation. Strauss Borrelli PLLC is investigating the incident and the rights of potentially affected individuals. If you received a notice or believe your information was involved, you may fill out the secure contact form on this page to help verify potential claim eligibility.

Key Facts at a Glance

  • Entity Involved: Seyfarth Shaw LLP (Legal Services)
  • Incident Type: Data security incident; the specific cause was not stated in the available regulatory listing
  • Date of Incident: August 18, 2026 to August 18, 2026
  • Discovery Date: Not disclosed in the available regulatory listing
  • Official Notice Date: September 18, 2026
  • Exposed Information: Names and Social Security numbers may have been involved
  • Affected Population: 56,755 reportedly affected individuals

What Happened?

According to an entry on the California Attorney General’s data security breach portal, Seyfarth Shaw LLP reported an incident date of August 18, 2026. The portal lists September 18, 2026 as the reported date, and the incident information also references state Attorney General filings in Texas, Massachusetts, and California. The available California listing does not explain how the incident occurred, when it was discovered, whether a third party was involved, or whether information was removed from a system.

Because those technical details have not been established in the materials reviewed, it would be premature to characterize the event as ransomware, phishing, or a vendor compromise. Individuals should rely on their personalized notice for information about whether their records were implicated. They should also remain cautious of messages claiming to concern the incident, particularly if a sender requests credentials, payment, or sensitive information.

What Information Was Exposed?

Regulatory incident data indicates that names and Social Security numbers may have been involved in the Seyfarth Shaw LLP incident. The specific combination of information may differ from person to person, so a recipient’s individual notice should be reviewed carefully.

A name combined with a Social Security number can increase the risk of identity theft, fraudulent credit applications, tax fraud, and convincing phishing attempts. Because the affected entity operates in legal services, criminals could also attempt professional-services impersonation, fraudulent invoice requests, vendor payment changes, employee W-2 scams, or messages that appear to reference confidential legal or workplace matters. These risks do not establish that misuse has occurred.

What Should You Do Next?

  1. Review your notice: Confirm which information may have been involved, what protection services are available, and any enrollment deadline. Contact the organization through independently verified contact information rather than links in an unexpected email or text.
  2. Check your credit reports: Review reports from Equifax, Experian, and TransUnion for unfamiliar accounts, inquiries, addresses, or employers. Continue monitoring because identity misuse may not appear immediately.
  3. Consider a credit freeze: A free security freeze can make it harder for someone to open new credit in your name. Place the freeze separately with each nationwide credit bureau and store the confirmation details securely.
  4. Watch for legal-services impersonation: Independently verify invoice changes, wire instructions, document-sharing requests, tax-form messages, and password-reset prompts. Be especially cautious when a sender creates urgency or claims that confidentiality prevents verification.
  5. Preserve relevant records: Keep the incident notice, envelopes, emails, screenshots, credit reports, fraud alerts, and receipts for expenses. Document suspicious activity and report identity theft through the appropriate financial institution and government channels.

Your Legal Rights

People whose personal information was involved in a reported data incident may have rights under federal or state privacy, consumer-protection, and data-security laws. The available options depend on where the person lives, the information involved, the circumstances of the incident, and whether measurable losses or other harm occurred.

Potentially affected individuals may be able to seek remedies such as reimbursement for documented losses, compensation for time spent addressing identity theft, or improved security practices. The availability of any claim is not guaranteed, and receiving a notice does not by itself prove negligence or misuse. Preserve the notice and related records, observe applicable deadlines, and consider consulting an attorney about your particular circumstances.

Why Hire Strauss Borrelli PLLC?

The firm represents consumers in privacy and data-security matters and can evaluate regulatory notices, the information reportedly involved, and potential remedies. An attorney can also help preserve evidence, explain relevant deadlines, and assess whether an individual may qualify to participate in a claim. Any review should be based on the person’s notice and circumstances, and no outcome can be guaranteed.

If you received a breach notification letter from Seyfarth Shaw:

We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.

Data Breach Website Blog Form

Contact Us

Learn about your legal rights

Name
Terms & Conditions and Privacy Policy

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

Contact Us Now

Data Breach Website Blog Form

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.
PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.

PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY