Frankel Loughran Starr & Vallone LLP was the subject of a data breach notification filed with the IN Attorney General. The AG filing was recorded on February 26, 2026. The breach or discovery date reported in the filing is December 12, 2025.
Data Exposed
Frankel Loughran Starr & Vallone LLP was the subject of a data breach notification filed with the IN Attorney General. The AG filing was recorded on February 26, 2026. The breach or discovery date reported in the filing is December 12, 2025.
Frankel Loughran Starr & Vallone LLP is a professional services firm that handles sensitive financial, tax, and legal advisory work for individuals and corporate clients. Organizations of this nature occupy a position of immense trust, routinely collecting and maintaining vast repositories of confidential records. Because their core operations involve managing complex financial portfolios, preparing corporate and personal tax returns, and executing comprehensive wealth management and legal strategies, they inevitably acquire an extraordinary volume of highly sensitive personal identifiable information. This includes not only everyday contact details but also deep financial histories, business ledgers, and government-issued identification numbers necessary for regulatory compliance and strategic advisory services. The security incident reported by Frankel Loughran Starr & Vallone LLP to the Indiana Attorney General in 2026 highlights the persistent vulnerabilities faced by professional service firms that store high-value data on digital networks. While professional practices maintain strict internal confidentiality protocols regarding physical files and client communications, digital infrastructure is frequently targeted by sophisticated cybercriminals seeking lucrative data troves. Incidents of this scale typically involve unauthorized access to internal file servers, compromised employee credentials, or vulnerabilities within third-party vendor software utilized for document sharing and accounting. Threat actors increasingly deploy ransomware or advanced persistent threats to infiltrate these networks, exploiting gaps in perimeter defense to harvest confidential data before detection mechanisms can isolate the breach. The exposure of data entrusted to a financial, tax, and legal advisory firm carries severe, long-term consequences for affected clients. Because Frankel Loughran Starr & Vallone LLP processes comprehensive financial and tax records, compromised files frequently include full names, Social Security numbers, dates of birth, tax return documents, wage and compensation details, and direct deposit or banking account numbers. When Social Security numbers and tax information fall into the wrong hands, victims face an immediate and elevated risk of tax fraud, where bad actors file fraudulent returns to intercept refunds. Furthermore, exposed banking details and financial account numbers open the door to unauthorized wire transfers, account takeovers, and synthetic identity theft, requiring victims to spend years monitoring their credit reports and financial statements. Under federal and state data protection frameworks, including the Indiana Consumer Data Protection Act and applicable provisions of the Federal Trade Commission Act, firms that collect and store sensitive personal and financial data have a legal duty to implement and maintain reasonable security measures. These legal obligations require organizations to deploy robust encryption, multi-factor authentication, regular network vulnerability assessments, and strict access controls to prevent unauthorized extraction. The occurrence of a data breach of this magnitude serves as a strong indicator that reasonable security standards may have been compromised or neglected, representing a potential failure of the firm's legal duty to protect confidential client data from foreseeable cyber threats. Receiving a formal data breach notification letter from Frankel Loughran Starr & Vallone LLP is an official acknowledgment that your private information was compromised due to inadequate security safeguards. Legally, this notification establishes the necessary standing to participate in a class action lawsuit aimed at holding the firm accountable for failing to protect your sensitive data. Importantly, victims do not need to prove that financial loss or identity theft has already occurred to seek legal recourse; the increased risk of future harm and the loss of privacy are sufficient grounds for legal action. Our firm investigates these data breach matters on a strict contingency fee basis, meaning you pay nothing out of pocket and owe no legal fees unless we successfully recover compensation on your behalf.
Based on the data types reported, affected individuals face:
Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
What the Indiana data breach notification law and federal statutes entitle you to recover:
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.
Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.
Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under Indiana data breach notification law and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.
Accepting free credit monitoring from Frankel Loughran Starr & Vallone LLP does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by Frankel Loughran Starr & Vallone LLP during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Received a notification letter from Frankel Loughran Starr & Vallone LLP?
What it means and what to do next.
Frankel Loughran Starr & Vallone LLP breach?
Free case review · No fee unless you win