CA · AG Filing: Feb 28, 2025
No cost. No obligation. If your data was exposed by Kronick Moskovitz Tiedemann & Girard, you may be entitled to financial compensation.
Start Free Review →Based on the data types reported in this filing:
Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
Kronick Moskovitz Tiedemann & Girard was the subject of a data breach notification filed with the CA Attorney General. The AG filing was recorded on February 28, 2025. The breach or discovery date reported in the filing is July 19, 2024.
From the AG filing description
Kronick Moskovitz Tiedemann & Girard is a prominent, full-service California law firm that provides comprehensive legal representation to public agencies, private corporations, and individuals across complex practice areas including municipal law, labor and employment, corporate transactions, and civil litigation. Because of the sophisticated nature of their legal work, the firm routinely collects, analyzes, and retains vast quantities of highly sensitive documentation. This includes confidential client files, proprietary corporate strategies, internal personnel records, financial statements, and detailed personal identifiers of opposing parties, employees, and corporate stakeholders. The high-stakes nature of legal practice means that law firms like Kronick Moskovitz Tiedemann & Girard serve as concentrated repositories of valuable and confidential information, making them prime targets for malicious cybercriminals seeking to exploit inadequately secured digital assets. In 2025, Kronick Moskovitz Tiedemann & Girard reported a significant data security incident to the California Attorney General's office, prompting widespread concern among current and former clients, employees, and associated individuals whose private information was entrusted to the firm. While the full scope of the incident continues to be evaluated, security events affecting major legal institutions typically involve sophisticated cyberattacks such as unauthorized access to network environments, ransomware deployment, or compromise of third-party vendor platforms. Law firm networks are especially vulnerable due to the necessity of sharing large volumes of sensitive data externally with co-counsel, expert witnesses, corporate clients, and judicial systems. When cyber threat actors successfully breach these digital perimeters, they often exfiltrate gigabytes of confidential files before detection, leaving affected organizations scrambling to determine the exact pathways of compromise and the full extent of the exposure. The data compromised in incidents involving law firms typically encompasses a devastating combination of personally identifiable information (PII) and highly sensitive professional documentation. Depending on the nature of the specific files accessed, exposed records frequently include full legal names, Social Security numbers, dates of birth, home addresses, financial account details, tax records, and internal personnel or compensation data. For clients involved in litigation or corporate transactions, the breach may also expose proprietary business strategies, trade secrets, and deeply personal communications. The exposure of this information creates severe, long-term risks for victims. Social Security numbers and dates of birth can be weaponized by identity thieves to open fraudulent financial accounts, apply for unauthorized loans, or commit tax fraud. Furthermore, the compromise of confidential legal records undermines the fundamental expectation of attorney-client privilege and privacy, exposing victims to targeted scams, extortion attempts, and persistent digital harassment. As a professional services entity operating within California, Kronick Moskovitz Tiedemann & Girard had strict legal and ethical obligations to safeguard the sensitive data entrusted to its care. Under California's data breach notification statutes, as well as common law duties of confidentiality and reasonable care, the firm was required to implement and maintain robust administrative, physical, and technical safeguards to protect digital infrastructure against foreseeable cyber threats. The occurrence of a data breach of this magnitude strongly suggests potential failures in adhering to these rigorous cybersecurity standards—such as utilizing outdated encryption protocols, failing to enforce multi-factor authentication, neglecting regular vulnerability assessments, or lacking adequate employee security training. Under applicable state laws, organizations that fail to maintain reasonable security measures can be held legally accountable for the foreseeable consequences of a data compromise. Receiving a formal data breach notification letter from Kronick Moskovitz Tiedemann & Girard serves as a formal legal acknowledgment that your private information was compromised due to the firm's security failures. Under California law, the receipt of such a notification establishes legal standing to participate in a class action lawsuit aimed at demanding accountability, securing financial compensation, and compelling the implementation of enhanced security measures. Critically, affected individuals do not need to prove that they have already suffered actual financial loss or identity theft to pursue legal action; the increased risk of future harm and the loss of data privacy are sufficient grounds for litigation. Our law firm handles these complex data privacy cases on a strict contingency fee basis, meaning there are never any out-of-pocket costs or upfront fees for affected individuals, and we only collect a fee if we successfully recover compensation on your behalf.
You may have been affected by the Kronick Moskovitz Tiedemann & Girard data breach if:
Common categories of compensation in data breach class actions
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.
Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.
Several state data breach laws provide for statutory minimum damages — fixed amounts recoverable per affected individual regardless of actual loss. These provisions exist specifically to make legal action viable for victims who have not yet experienced direct harm.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
Applicable State Law
This breach was reported under the California Consumer Privacy Act (CCPA), which mandates notification and establishes your right to seek damages.
No. Under California Consumer Privacy Act (CCPA) and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
Statutes of limitations for data breach claims vary by state but typically run 2–4 years. Depending on when you learned of the breach, you may still have time. Contact our office for a free eligibility review — there is no cost to find out.
Accepting free credit monitoring from Kronick Moskovitz Tiedemann & Girard does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by Kronick Moskovitz Tiedemann & Girard during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Learn how to participate in the class action and what compensation you may be entitled to.
Join the Class Action →Use our verification tool to confirm your letter matches this official AG filing.
Verify My Notice LetterThis case file references a public filing made with the state filing in CA. This website is not affiliated with, endorsed by, or operated by any state government agency.
Kronick Moskovitz Tiedemann & Girard breach?
Free case review · No fee unless you win