Singleton Schreiber LLP was the subject of a data breach notification filed with the IN Attorney General. The AG filing was recorded on May 27, 2026. The breach or discovery date reported in the filing is February 19, 2026.
Data Exposed
Singleton Schreiber LLP was the subject of a data breach notification filed with the IN Attorney General. The AG filing was recorded on May 27, 2026. The breach or discovery date reported in the filing is February 19, 2026.
Singleton Schreiber LLP is a prominent law firm renowned for handling complex litigation, including mass torts, catastrophic personal injury, environmental contamination, and civil rights cases. Because of the nature of its high-stakes practice, the firm routinely collects, processes, and maintains vast quantities of deeply sensitive information. This includes not only confidential client intake files, medical records, and detailed financial disclosures, but also personnel files, retainer agreements, and sensitive communications related to active and pending litigation. As a custodian of highly confidential and privileged data, Singleton Schreiber LLP operates as a primary repository for private documentation that, if compromised, exposes individuals to severe privacy violations. In 2026, reports surfaced regarding a significant data security incident involving Singleton Schreiber LLP that was formally reported to the Indiana Attorney General. While exact technical forensics remain under active investigation, security incidents affecting major legal practices typically involve sophisticated cyberattacks such as unauthorized network intrusions, ransomware deployment, or third-party vendor compromises. Law firms are prime targets for malicious actors seeking to exploit vulnerabilities in network perimeters, harvest intellectual property, or leverage confidential client records for extortion. When an enterprise with access to deeply personal and legal documents suffers a security failure, it often indicates vulnerabilities in network monitoring, credential management, or encryption protocols. The exposure resulting from a breach at a major law firm compromises an array of sensitive data categories, each carrying distinct and severe risks for affected individuals. Exposed information frequently includes full names, dates of birth, Social Security numbers, banking details, confidential medical histories, and sensitive legal documentation. When Social Security numbers and personal identifiers are leaked, victims face an elevated risk of identity theft, fraudulent credit card applications, and unauthorized tax filings. Furthermore, the compromise of confidential legal files and medical records can lead to targeted spear-phishing campaigns, medical identity theft, and severe breaches of personal privacy that are exceptionally difficult to remediate. Under applicable state and federal data protection standards, including the Indiana Disclosure of Security Breach Law, organizations entrusted with sensitive personal information have a legal duty to implement and maintain reasonable security procedures. This obligation requires robust cybersecurity measures, including multi-factor authentication, regular penetration testing, network segmentation, and prompt patching of known vulnerabilities. The occurrence of a data breach of this magnitude serves as strong prima facie evidence that the firm may have failed to uphold its statutory and common-law duties of care, leaving its clients, employees, and associated parties vulnerable to foreseeable cyber threats. Receiving an official data breach notification letter from Singleton Schreiber LLP is a formal acknowledgment that your private information was compromised due to inadequate security safeguards. Legally, the receipt of this notice establishes the standing necessary to participate in a class action lawsuit aimed at holding the firm accountable for its security failures. Under prevailing legal standards, victims do not need to prove that they have already suffered actual financial loss or identity theft to seek legal recourse; the increased risk of future harm and the loss of privacy are sufficient grounds for action. Our firm handles data breach and privacy litigation on a contingency fee basis, meaning there are never any out-of-pocket costs, and you pay nothing unless we successfully recover compensation on your behalf.
Based on the data types reported, affected individuals face:
Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
What the Indiana data breach notification law and federal statutes entitle you to recover:
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.
HIPAA violations carry civil penalties between $100 and $50,000 per violation. Where a healthcare organization's negligence led to the exposure of protected health information, class members may recover statutory damages in addition to actual losses.
Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.
Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under Indiana data breach notification law and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.
If Singleton Schreiber LLP is a covered healthcare entity or business associate under HIPAA, affected patients have additional rights — including the right to an HHS complaint. These HIPAA violations also strengthen civil damages claims. Consult an attorney to understand your full remedies.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.
Accepting free credit monitoring from Singleton Schreiber LLP does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Received a notification letter from Singleton Schreiber LLP?
What it means and what to do next.
Singleton Schreiber LLP breach?
Free case review · No fee unless you win