Reported to the OR Attorney General on August 5, 2026.
OR residents may qualify for compensation. Free attorney review — no obligation, no upfront cost.
Check My Rights →Wilmer Cutler Pickering Hale and Dorr LLP was the subject of a data breach notification filed with the OR Attorney General. The AG filing was recorded on August 5, 2026. The breach or discovery date reported in the filing is May 8, 2026.
Wilmer Cutler Pickering Hale and Dorr LLP is a globally renowned, elite multinational law firm specializing in high-stakes litigation, intellectual property, regulatory compliance, corporate transactions, and government investigations. Operating at the highest levels of the legal sector, the firm regularly counsels Fortune 500 corporations, financial institutions, sovereign governments, and high-profile executives. Because of the extraordinary sensitivity of the matters it handles, WilmerHale maintains repositories of deeply confidential, proprietary, and privileged information, including corporate trade secrets, merger and acquisition strategies, intellectual property portfolios, regulatory filings, and extensive personal identifying information (PII) of clients, opposing parties, employees, and corporate executives. In 2026, Wilmer Cutler Pickering Hale and Dorr LLP reported a significant data security incident to the Oregon Attorney General. While the precise vector of the intrusion is still being fully investigated, security incidents affecting major legal institutions typically involve sophisticated cyberattacks such as unauthorized network access, malware deployment, targeted phishing campaigns, or vulnerabilities within third-party vendor platforms used for document review and collaborative case management. Because law firms serve as central repositories for vast amounts of interconnected data across multiple corporate and individual clients, an intrusion into their IT environment can compromise multiple security layers, potentially allowing unauthorized actors to dwell undetected within their network and extract sensitive document archives. The data exposed in a breach of this magnitude typically includes a devastating combination of personally identifiable information and highly sensitive professional documentation, such as full legal names, Social Security numbers, dates of birth, home addresses, personal email addresses, banking and wire transfer details, tax records, and confidential internal communications. For individuals whose data is compromised, the exposure of core identifiers like Social Security numbers and financial details creates an immediate and long-lasting risk of identity theft, synthetic fraud, and unauthorized financial account takeover. Furthermore, because law firm data often includes sensitive corporate governance and legal strategy files, affected individuals face elevated risks of targeted spear-phishing, business email compromise, and reputational or professional harm. As a premier legal entity entrusted with sensitive data, Wilmer Cutler Pickering Hale and Dorr LLP was bound by stringent legal, professional, and ethical duties to protect this information under state data protection statutes, common law negligence standards, and industry-standard frameworks such as the FTC Act and rules governing client confidentiality. These obligations required the firm to implement and maintain robust administrative, physical, and technical safeguards, including multi-factor authentication, advanced endpoint detection and response, rigorous encryption protocols, and regular network penetration testing. The occurrence of a data breach strongly suggests potential shortcomings or failures in these foundational security measures, raising serious questions about whether the firm lived up to its legal duty of care. Receiving a data breach notification letter from Wilmer Cutler Pickering Hale and Dorr LLP serves as formal legal confirmation that your sensitive personal information was compromised due to inadequate security practices. Under modern data breach jurisprudence, the receipt of this letter establishes the legal standing necessary to initiate or join a class action lawsuit against the firm. Importantly, affected individuals do not need to wait until they experience actual financial loss or identity theft to seek legal recourse; the increased risk and imminent threat of future harm are sufficient to bring a claim. Our law firm is currently investigating potential class action claims on behalf of all impacted individuals on a contingency fee basis, meaning there are never any out-of-pocket costs or attorney fees unless we successfully recover compensation on your behalf.
Based on the data types reported in this filing, affected individuals face the following specific risks:
Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
Under the Oregon Consumer Information Protection Act, you may have a legal claim against Wilmer Cutler Pickering Hale and Dorr LLP if any of the following apply:
Applicable law: This breach was reported under the Oregon Consumer Information Protection Act, which establishes your right to seek damages from Wilmer Cutler Pickering Hale and Dorr LLP.
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.
Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.
Several state data breach laws provide for statutory minimum damages — fixed amounts recoverable per affected individual regardless of actual loss. These provisions exist specifically to make legal action viable for victims who have not yet experienced direct harm.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under Oregon Consumer Information Protection Act and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.
Accepting free credit monitoring from Wilmer Cutler Pickering Hale and Dorr LLP does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by Wilmer Cutler Pickering Hale and Dorr LLP during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Received a notification letter from Wilmer Cutler Pickering Hale and Dorr LLP?
Read our dedicated guide — what the letter means and exactly what to do.
If you were affected by the Wilmer Cutler Pickering Hale and Dorr LLP data breach, you may be entitled to compensation. Submit your information below for a free attorney review — no obligation, no upfront cost.
Source: State Attorney General filing, OR
View Official AG Filing →Wilmer Cutler Pickering Hale and Dorr LLP breach?
Free case review · No fee unless you win