GrayRobinson P.A., a full-service law and lobbying firm, detected unauthorized access to its systems on March 24, 2025. The incident occurred between March 5 and March 24, 2025. The firm engaged cybersecurity experts and notified law enforcement, confirming potential exposure of limited data on April 13, 2026. Official written notifications to impacted individuals began on April 24, 2026.
The breach involved personally identifiable information such as first and last name, date of birth, Social Security number, driver's license number, state or government ID, and financial account information. Protected health information, including medical and health insurance information, was also exposed. The incident affected 65,113 individuals across the United States. While no evidence of data misuse has been publicly confirmed, the full extent of the impact remains unclear.
More details may emerge as investigations continue and notifications proceed.