Cyber Incident Victim: Blank Rome LLP
Timeline
Summary
Blank Rome LLP experienced a data breach after an attorney was tricked into uploading confidential client files to an external Google Drive account, exposing personal information of over 57,000 individuals including names, Social Security numbers, addresses, phone numbers, dates of birth, driver’s license numbers, financial account details, and medical and health insurance data. The firm delayed notifying those affected, which may violate breach notification laws, and subsequently faced a proposed class action alleging negligence, breach of contract, and violations of statutes such as the FTC Act and HIPAA, seeking compensatory and punitive damages as well as injunctive relief.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On May 21, 2026, an attorney at Blank Rome LLP was deceived by an individual posing as a member of the firm’s IT department into uploading sensitive client files to an external Google Drive account. This action resulted in the unauthorized exposure of personal information belonging to at least 57,554 individuals associated with the firm. Blank Rome LLP is a Philadelphia‑based Am Law 100 law firm that employs approximately 800 attorneys across 16 offices in the United States and abroad. The firm did not issue notification to the affected individuals until late June 2026.

The compromised data included names, Social Security numbers, physical and email addresses, phone numbers, dates of birth, taxpayer identification numbers, driver’s license numbers, state ID card numbers, passport numbers, financial‑account numbers, payment card information, medical information, and health insurance information. The breach affected current, former, and prospective clients as well as other individuals whose data was stored on the firm’s systems. Individuals whose information was exposed reported injuries such as invasion of privacy, lost time and money spent responding to the breach, emotional distress, increased spam communications, and a reduced value of their personal information. The exposure also heightened the risk of fraud and identity theft for the affected individuals.
In early July 2026, a proposed class action lawsuit was filed in the United States District Court for the Eastern District of Pennsylvania, alleging that Blank Rome LLP negligently failed to protect the personal information and violated duties under common law, contract law, industry standards, the Federal Trade Commission Act, and the Health Insurance Portability and Accountability Act. The lawsuit, led by plaintiff Laura Delapaz and represented by Strauss Borrelli PLLC, seeks compensatory, punitive, and statutory damages, restitution, equitable and injunctive relief, attorneys’ fees and costs, and pre‑ and post‑judgment interest. The complaint asserts claims of negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, breach of confidence, and violations of the California Unfair Competition Law, the California Consumer Privacy Act, and the California Customer Records Act. Concurrently, the incident is under investigation by the law firm Schubert Jonckheer & Kolbe, which issued a privacy alert regarding the breach and the potential violation of federal or state data breach notification laws due to the delayed notice.