Fragomen, Del Rey, Bernsen & Loewy Data Breach Investigation
Fragomen, Del Rey, Bernsen & Loewy, LLP reported a data incident that may have involved individuals’ names and passport numbers, according to state regulatory information. The available materials do not disclose how many people were affected or describe the incident method. Strauss Borrelli PLLC is investigating the incident and its potential impact on affected individuals. If you received a notice, you may fill out the secure contact form on this page to ask whether you may qualify to pursue a claim.
Key Facts at a Glance
- Entity Involved: Fragomen, Del Rey, Bernsen & Loewy, LLP (Legal Services)
- Incident Type: Not specified in the available regulatory materials
- Date of Incident: May 4 to May 5, 2026
- Discovery Date: Not disclosed in the available materials
- Official Notice Date: October 2, 2026
- Exposed Information: Names, passport numbers, alien registration numbers, and Social Security numbers. But information impacted varies by individual
- Affected Population: Not disclosed in the available materials
What Happened?
According to the state regulatory information available for this incident, Fragomen, Del Rey, Bernsen & Loewy, LLP reported an incident date of May 5, 2026. A notice was publicly listed by the California Attorney General on October 2, 2026, and the incident information also identifies a filing in Vermont. The available materials indicate that personal information may have been involved, but they do not explain whether the event resulted from unauthorized access, ransomware, phishing, a vendor compromise, or another cause.
The available information also does not identify a discovery date, the duration of any unauthorized activity, the systems involved, or whether a third party played a role. Individuals who received a notification letter should retain it and review its personalized description carefully because the information affected may differ among recipients. Additional facts may become available through later company disclosures or regulatory updates.
What Information Was Exposed?
The reported data categories are names and passport numbers. The available regulatory materials do not identify other exposed information, and they do not establish that both categories were involved for every person. A passport number can be particularly sensitive because it may be used in identity-verification scams or fraudulent document requests.
Because the entity operates in legal services, affected individuals should be alert to messages impersonating attorneys, support staff, government agencies, or document-processing services. Criminals could potentially use accurate personal details to make requests for passport copies, immigration documents, payments, account credentials, or updated billing information appear credible. Businesses should also watch for vendor invoice manipulation and employee impersonation attempts.
What Should You Do Next?
- Review and preserve your notice: Keep the complete letter, envelope, and related emails. Note which information the notice says was involved for you and save records of suspicious messages, expenses, or identity-related problems.
- Secure relevant accounts: Change passwords for email, document portals, and other accounts that may contain legal or identity records. Use unique passwords and enable multifactor authentication wherever it is available.
- Watch for passport-related scams: Be cautious of unexpected requests to verify a passport number, upload identity documents, pay processing fees, or follow links concerning legal or government services. Confirm requests through a trusted telephone number or official website.
- Monitor your credit reports: Review reports from all three major credit bureaus for unfamiliar accounts or inquiries. Consider a fraud alert or credit freeze if you believe your information may be misused.
- Document possible harm and ask about your options: Track fraudulent charges, lost time, replacement-document costs, and other consequences. If you received a notice, you may use the secure contact form on this page to ask whether the reported incident may support a claim.
Your Legal Rights
People whose personal information was involved in a reported security incident may have rights under state privacy, data-security, consumer-protection, or breach-notification laws. The rights available depend on the person’s state, the information involved, what occurred, and whether the incident caused measurable harm. Potential issues may include the adequacy and timing of notice, safeguards used to protect personal information, and reimbursement for documented losses.
Receiving a notice does not automatically establish that identity theft occurred or that a legal claim will succeed. However, recipients may wish to preserve the notice, communications, receipts, credit reports, and records of suspicious activity. Deadlines may apply, so affected individuals can consider consulting a qualified attorney about their circumstances. This general information is not individualized legal advice.
Why Hire Strauss Borrelli PLLC?
Strauss Borrelli PLLC represents individuals in privacy and data-security matters and can assess regulatory notices, the types of information reportedly involved, and any documented consequences. A legal review may help an affected person understand whether applicable law provides a potential remedy and what evidence should be preserved. Contacting counsel for an evaluation does not guarantee that a claim exists or that any particular result will be achieved.
If you received a breach notification letter from Fragomen, Del Rey, Bernsen & Loewy:
We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.










