Active InvestigationInvestigation Open

Curtland Company PC Data Breach — Case File

IN · AG Filing: Aug 7, 2026 · Recently disclosed — legal window is open

No cost. No obligation. If your data was exposed by Curtland Company PC, you may be entitled to financial compensation.

Start Free Review →

Exposed Data — What's at Risk

Based on the data types reported in this filing:

Identity Theftcritical risk

Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.

Identity Verification Bypassmedium risk

Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.

How the Breach Occurred

Curtland Company PC was the subject of a data breach notification filed with the IN Attorney General. The AG filing was recorded on August 7, 2026. The breach or discovery date reported in the filing is March 17, 2026.

From the AG filing description

298Curtland Company PC operates as a specialized professional services firm, functioning primarily as a private practice law firm or corporate consultancy handling complex legal, financial, and regulatory matters for individuals and businesses across Indiana. Because of the intimate and high-stakes nature of its work, 298Curtland Company PC routinely collects, processes, and stores an extensive volume of confidential information. This includes sensitive client records, proprietary corporate data, financial account details, tax documents, Social Security numbers, and detailed internal communications necessary for managing litigation, corporate restructuring, and advisory services. The accumulation of such high-value data makes the firm a prime target for malicious cyber actors seeking to exploit vulnerabilities for financial gain. In 2026, 298Curtland Company PC formally reported a significant cybersecurity incident to the Indiana Attorney General, triggering mandatory notification protocols for affected individuals. While organizations of this scale frequently encounter sophisticated threats—ranging from unauthorized database access and third-party vendor compromises to targeted ransomware deployments and credential harvesting—such an incident typically signals a breakdown in perimeter defense or inadequate network segmentation. When a professional services firm is compromised, malicious actors can often dwell undetected within internal networks for weeks or months, quietly exfiltrating proprietary files and confidential client databases before deploying encryption mechanisms or demanding extortion. The data compromised in the 298Curtland Company PC security incident encompasses a dangerous mixture of personally identifiable information (PII) and highly sensitive financial or legal records. The exposure of Social Security numbers, dates of birth, full names, and financial account details strips away foundational layers of privacy, creating immediate and long-term risks for victims. When identifiers of this caliber are leaked, affected individuals face a severe, ongoing threat of identity theft, unauthorized credit openings, tax fraud, and targeted spear-phishing campaigns. Unlike a temporary operational disruption, the permanent exposure of foundational identity data leaves victims vulnerable to financial exploitation for years to come. Under Indiana state data breach notification statutes, alongside broader regulatory frameworks such as the Federal Trade Commission Act governing unfair and deceptive trade practices, entities like 298Curtland Company PC have a strict legal duty to implement and maintain reasonable security measures to safeguard private consumer and client data. The occurrence of a widespread data breach strongly suggests potential failures in fulfilling these legal obligations, such as failing to maintain robust encryption standards, neglecting timely software patch management, or omitting multi-factor authentication across sensitive internal systems. Under the law, organizations that collect sensitive data assume a corresponding responsibility to protect it; when those safeguards fail, the organization may be held legally accountable for the resulting exposure. Receiving a data breach notification letter from 298Curtland Company PC serves as formal legal acknowledgment that your private information was compromised due to inadequate security infrastructure. Under modern class action jurisprudence, the receipt of such a letter provides the necessary legal standing to pursue a claim, and courts have increasingly recognized that the heightened, imminent risk of identity theft constitutes a concrete injury—meaning you do not have to wait until you experience actual financial loss to take legal action. Our firm is actively investigating potential class action claims against 298Curtland Company PC to hold them accountable for this security failure. We handle these cases on a strict contingency fee basis, meaning there is never any out-of-pocket cost or financial risk to you unless we successfully recover compensation on your behalf.

Quick Facts

State Filed
IN
Date Reported to AG
Aug 7, 2026
Date of Breach
Mar 17, 2026
Records Affected
Not disclosed
Status
Investigation Open
Last Updated
Oct 5, 2026
Data Types Exposed
Full NameSocial Security NumberDate of BirthHome AddressFinancial Account DetailsTax Return InformationLegal and Case RecordsPhone Number and Email Address

Were You Affected?

You may have been affected by the Curtland Company PC data breach if:

  • You received a written data breach notification letter from Curtland Company PC
  • You are or were a customer, patient, or employee of Curtland Company PC
  • Your information was held by Curtland Company PC in IN
  • Your bank or payment card data was potentially exposed

Your Rights as a Victim

Common categories of compensation in data breach class actions

Lost Time & Remediation Costs

The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.

Identity Theft Protection Costs

Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.

Banking & Account Fees

Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.

Statutory Minimum Damages

Several state data breach laws provide for statutory minimum damages — fixed amounts recoverable per affected individual regardless of actual loss. These provisions exist specifically to make legal action viable for victims who have not yet experienced direct harm.

Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.

Applicable State Law

This breach was reported under the Indiana data breach notification law, which mandates notification and establishes your right to seek damages.

Frequently Asked Questions

Do I need proof that my data was misused to file a claim against Curtland Company PC?

No. Under Indiana data breach notification law and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.

How much does filing a claim cost?

Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.

My Social Security Number was exposed. What should I do right now?

Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.

My financial account data was exposed. Can the bank recover my losses?

Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.

Is there a deadline to file a claim?

State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.

What if Curtland Company PC offered me free credit monitoring after the breach?

Accepting free credit monitoring from Curtland Company PC does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.

Do I need to have received a notice letter to be eligible?

Not necessarily. Many data breach victims are never notified directly. If your personal information was held by Curtland Company PC during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.

Filing Window Open

Received a Notice Letter?

Cases are filed first-come, first-served. Submit now for a free attorney review — no cost, no obligation.

Start typing to find a matching case, or enter a company not yet listed.

Attach a copy of your data breach notification letter. Accepted: PDF, JPG, PNG — max 10 MB.

No attorney-client relationship is created by submitting this form. Attorney Advertising.

You Have a Legal Claim

Learn how to participate in the class action and what compensation you may be entitled to.

Join the Class Action →

Received a notice letter?

Use our verification tool to confirm your letter matches this official AG filing.

Verify My Notice Letter

This case file references a public filing made with the state filing in IN. This website is not affiliated with, endorsed by, or operated by any state government agency.

Curtland Company PC breach?

Free case review · No fee unless you win

Call Now