Berger & Williams, LLP was the subject of a data breach notification filed with the CA Attorney General. The AG filing was recorded on May 5, 2026. The breach or discovery date reported in the filing is February 6, 2025.
Data Exposed
Berger & Williams, LLP was the subject of a data breach notification filed with the CA Attorney General. The AG filing was recorded on May 5, 2026. The breach or discovery date reported in the filing is February 6, 2025.
As a prominent and established law firm, Berger & Williams, LLP handles highly sensitive, confidential, and privileged matters for corporate and individual clients alike. Because of the nature of legal practice, the firm routinely collects, stores, and processes vast quantities of highly sensitive personal and financial data. This includes comprehensive client files, corporate governance documents, detailed financial records, intellectual property, and extensive personnel files for attorneys and staff. To effectively litigate, advise, and negotiate on behalf of their clients, legal institutions like Berger & Williams, LLP are trusted repositories of critical, high-value information that makes them primary targets for malicious actors seeking to exploit systemic vulnerabilities. In 2026, Berger & Williams, LLP formally reported a significant cybersecurity incident to the California Attorney General, alerting clients, employees, and regulatory authorities to an unauthorized compromise of its digital infrastructure. While law firm data breaches can stem from various threat vectors—such as sophisticated ransomware deployments, third-party vendor compromises, or unauthorized intrusion into legacy document management systems—the incident underscores the growing vulnerability of legal institutions. Cybercriminals frequently target law firms not only to disrupt operations through extortion but also to harvest confidential records, attorney-client communications, and personally identifiable information that can be monetized on the dark web or leveraged for targeted spear-phishing campaigns. The data compromised in the Berger & Williams, LLP security incident reportedly exposes individuals to profound, multi-faceted risks. Depending on the scope of the breach, exposed records likely include full legal names, Social Security numbers, dates of birth, home addresses, banking and direct deposit details, and confidential tax or compensation records. Furthermore, because of the firm's legal practice areas, corporate or personal litigation files, trust account details, and sensitive legal correspondence may have been accessed. The exposure of Social Security numbers and financial account details creates an immediate and severe risk of identity theft, fraudulent credit applications, and unauthorized financial account takeovers, while compromised tax and compensation records leave victims vulnerable to tax refund fraud and targeted financial scams. Under California law, as well as broader common law principles governing the handling of sensitive consumer and employee information, Berger & Williams, LLP had a strict legal and ethical obligation to implement robust administrative, technical, and physical safeguards to protect the data entrusted to them. This duty encompasses maintaining up-to-date encryption standards, conducting regular vulnerability assessments, enforcing stringent access controls, and swiftly patching known software vulnerabilities. The occurrence of a data breach of this magnitude serves as a strong indicator that the firm may have failed to adhere to these foundational data security standards, potentially exposing them to legal liability for negligence, breach of implied contract, and violations of state consumer protection statutes. For current and former clients, employees, and associated individuals, receiving an official data breach notification letter from Berger & Williams, LLP is an official acknowledgment that their private information has been compromised. Crucially, under modern class action jurisprudence, affected individuals do not need to prove that they have already suffered actual financial loss or identity theft to pursue legal recourse; the mere increased risk of future harm and the unlawful exposure of confidential data is sufficient to establish legal standing. Our class action law firm is actively investigating the Berger & Williams, LLP data breach to hold the organization accountable for its security failures. We handle these cases on a contingency fee basis, meaning there are never any out-of-pocket costs or attorney fees unless we successfully recover compensation on your behalf.
Based on the data types reported, affected individuals face:
Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
What the California Consumer Privacy Act (CCPA) and federal statutes entitle you to recover:
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.
Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.
Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under California Consumer Privacy Act (CCPA) and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.
Accepting free credit monitoring from Berger & Williams, LLP does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by Berger & Williams, LLP during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Received a notification letter from Berger & Williams, LLP?
What it means and what to do next.
Berger & Williams, LLP breach?
Free case review · No fee unless you win