Menu
Browse

Cyber Incident Victim: Barton Gilman

Date:

Sep 2024

Location:

United States of America

Summary

Barton Gilman, a law firm with offices in Providence and Boston, is facing a class action lawsuit over a data breach that compromised personal information. The breach occurred in the firm's computer network, and the firm took approximately a year to detect it, delaying notification to affected individuals. The lawsuit, filed in federal court in Rhode Island, alleges negligence, breach of implied contract, and unjust enrichment, claiming the firm failed to implement adequate security measures and provide timely breach notice. The incident affected 3,375 residents across multiple states, and the plaintiff argues that the delayed response exacerbated harm and that offered credit monitoring is insufficient. The case raises broader concerns about data security practices in law firms.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

In September 2024, the computer network of Barton Gilman, a regional law firm with offices in Providence and Boston, was breached, resulting in the theft of personal information. The incident remained undetected by the firm for approximately one year, a delay that legal experts have identified as a critical failure in the firm's security protocols. The breach was not disclosed to affected individuals until December 23, 2025, when plaintiff Allison Hellested of Swansea received formal notice. This notification came after the firm had reported the incident to authorities in Massachusetts and Vermont in the same month, December 2025, as required by state breach notification laws. The firm's delayed detection and subsequent year-long gap before informing individuals form the central allegations in the ensuing legal action, with the plaintiff arguing this timeline significantly exacerbated potential harm to victims.

Cyber Incident Image

The data breach impacted a total of 3,375 residents across multiple states, exposing their personal information. In response to the discovery, Barton Gilman offered credit monitoring services to affected individuals, a measure the plaintiff's lawsuit contends is insufficient given the circumstances. Following the notification, Allison Hellested filed a putative class action lawsuit against the firm in the U.S. District Court in Rhode Island. The complaint asserts multiple legal claims, including negligence for failing to implement adequate data security measures, breach of implied contract for not safeguarding client information, and unjust enrichment for retaining benefits while providing inadequate protection. The case highlights the legal and reputational consequences for organizations, particularly law firms, that handle sensitive data and face scrutiny over their cybersecurity practices and breach response timelines. The litigation is ongoing, seeking damages and restitution for the class of individuals whose information was compromised.

Sources
Sources available to members
1 source