Severity Daily

IT and AI security incidents, checked against the primary source

Tag: dark web

  • Greenberg Traurig filed breach notices naming Social Security numbers in two states before publicly calling the exposure limited

    Greenberg Traurig filed breach notices naming Social Security numbers in two states before publicly calling the exposure limited

    Greenberg Traurig told two state regulators about a breach involving Social Security numbers on September 8 and September 9, 2026, days before it publicly characterized the incident as limited — and the filings, not the firm, are where the concrete facts are.

    What happened

    Greenberg Traurig, LLP, an international law firm with more than 3,200 attorneys, has reported a data breach to at least two state attorneys general. The filings are dated September 8, 2026 in Vermont and September 9, 2026 in California. The California entry gives a breach date of August 26, 2026.

    Those are the dates that matter for anyone tracking this, and they run in that order: the incident on August 26, the Vermont notification on September 8, the California notification on September 9, and the firm’s public statement on September 10. Nothing here is fresh as of this afternoon; what is new is that the regulatory record became legible this week.

    The Vermont Attorney General’s security breach notice database lists Greenberg Traurig, LLP with a report date of September 8, 2026, 10 Vermont residents affected, and the data element involved recorded as “Social Security Numbers.” Vermont does not publish the underlying consumer notice on the portal; it makes them available on request.

    The California Attorney General’s breach list carries the entry as “Greenberg Traurig, LLP (“GT”)” with a breach date of 08/26/2026 and a reported date of 09/09/2026. California’s threshold for appearing on that list is a notice sent to more than 500 California residents, so the California filing establishes a floor of 500 people in that state alone. A sample consumer notice is posted alongside the entry as a PDF; it could not be parsed by automated fetching, and its contents are therefore not reported here.

    Separately, on September 10, 2026, the firm made a public statement. It was given to Reuters and reached us through a secondary brief rather than from the firm directly, so it is reported here as relayed, not as read at first hand: the firm is described as saying that “an unauthorized actor” accessed documents and posted them on the dark web, that its “firm systems were not compromised or breached,” and that a “limited number of documents” and a “small number of affected clients” were involved. We could not read Reuters’ report or a statement on the firm’s own site.

    What the filings settle and what they do not

    Two things are established by primary record. First, Social Security numbers are in scope — that is Vermont’s own categorization on its portal, not a characterization by anyone reporting on the incident. Second, the population is not trivially small: California’s 500-resident threshold is a floor for one state, and ten Vermonters were notified in a state of roughly 650,000 people.

    Almost everything else is open. No total count of affected individuals appears in either filing. No discovery date is published. Neither portal states how the data was taken. And the firm’s own characterization — systems not compromised, documents nonetheless accessed and posted — points at some path that the firm has not described in anything we could read. A vendor, a third-party platform, a service the firm uses, an individual account: those are the ordinary candidates, and we are not going to pick one. It is worth being explicit that “our systems were not breached” and “client documents were taken and published” are not contradictory statements. They are, together, an incomplete one.

    We are also not going to attach an attacker to this. Ransomware leak-site trackers list the firm, and a claimed group name is circulating. No named victim, regulator, or filing we read attributes the incident to anyone, and this publication does not state attribution as fact.

    Why it matters

    The most useful thing about this incident is the order in which it became public. The firm’s public statement landed on September 10. The Vermont filing predates it by two days and the California filing by one, and the filings carry harder information than the statement does — a data element, a resident count, a breach date. A reader who followed only the coverage learned that the exposure was “limited.” A reader who checked two state portals learned that Social Security numbers were involved and that more than 500 Californians were notified.

    That gap is structural, not a criticism of any particular firm. A public statement is written to characterize; a state breach filing is written to satisfy a statutory disclosure form with fields for dates, counts, and data categories. The form is the part that does not compress. State attorney general portals are among the few primary sources in this field that are searchable, dated, and free, and they are checked far less often than vendor advisories are.

    The second thing worth drawing out is what a law firm’s breach means downstream, because it is not the firm’s own risk that is interesting. A firm of this size holds other organizations’ material — deal documents, litigation files, privileged communications, regulatory correspondence, and the personal data of its clients’ employees and customers. “A small number of affected clients” can be an accurate description of a compromise that is large for each of the clients involved. The unit of harm is not the law firm; it is the client whose file was in the set. Companies that received no notification because they are not the firm’s clients may still have people in those documents — opposing parties, witnesses, employees named in a matter.

    The third is the Social Security number detail, which changes what a reasonable response looks like. Document exposure without identifiers is a confidentiality problem. Document exposure with Social Security numbers is an identity-theft problem with a much longer tail, because the identifier does not rotate. Vermont’s portal records that element for this incident, which means the notification letters in at least one state told people their Social Security number was involved.

    What to do

    There is nothing to patch. The actions here are about finding out whether you are in scope.

    If your organization uses Greenberg Traurig, ask the firm directly whether your matters are in the affected set rather than waiting to be told. The firm has described the number of affected clients as small; that is a reason to ask, not a reason to assume you are outside it. Ask specifically what categories of your data were in the exposed documents, and whether any of your employees’ or customers’ personal data was in them.

    If you receive a notification letter, it will say which of your data elements were involved. Where a Social Security number is named, a credit freeze at all three bureaus is the response that actually matters, and it is free.

    If you maintain a third-party risk register, outside counsel belongs in it. Law firms are frequently omitted from vendor inventories because they are engaged by the legal department rather than procurement, and they routinely hold more sensitive material than the SaaS vendors that do get tracked. This incident is a reasonable prompt to check whether your register has one.

    If you monitor breaches as a practice, add the California and Vermont portals to what you check. Both carried this incident before it was widely reported, and both carry incidents that are never reported at all.

    Sourcing note

    The Vermont Attorney General’s security breach notice listing and the California Attorney General’s data breach list were both read directly. Vermont is the source for the September 8, 2026 report date, the count of 10 Vermont residents, and the “Social Security Numbers” data element. California is the source for the entry name “Greenberg Traurig, LLP (“GT”),” the August 26, 2026 breach date, and the September 9, 2026 reported date, and for the fact that a sample consumer notice is posted. That notice is a PDF and could not be parsed by automated fetching, so nothing from its text is reported here — it is the document most likely to answer the open questions below, and it is publicly available to anyone who can open it.

    The firm’s public statement of September 10, 2026 was not read at first hand. It was given to Reuters, and reached this story through a secondary brief summarizing that report. The quoted fragments — “an unauthorized actor,” “firm systems were not compromised or breached,” “limited number of documents,” “small number of affected clients” — are therefore reported as relayed and should be treated as weaker than the filing data above. Neither Reuters’ report nor a statement on the firm’s own website was reachable. The figure of more than 3,200 attorneys is the firm’s generally published size and is not drawn from any filing.

    Unresolved: the total number of individuals affected across all states, the discovery date, the mechanism by which documents were obtained given the firm’s statement that its systems were not compromised, whether any client organizations have been named, and whether additional state filings exist beyond Vermont and California. No attribution is asserted. Leak-site listings and claimed actor names were not treated as evidence and are not repeated here.