Severity Daily

IT and AI security incidents, checked against the primary source

Tag: data leak

  • Greenberg Traurig filed breach notices naming Social Security numbers in two states before publicly calling the exposure limited

    Greenberg Traurig filed breach notices naming Social Security numbers in two states before publicly calling the exposure limited

    Greenberg Traurig told two state regulators about a breach involving Social Security numbers on September 8 and September 9, 2026, days before it publicly characterized the incident as limited — and the filings, not the firm, are where the concrete facts are.

    What happened

    Greenberg Traurig, LLP, an international law firm with more than 3,200 attorneys, has reported a data breach to at least two state attorneys general. The filings are dated September 8, 2026 in Vermont and September 9, 2026 in California. The California entry gives a breach date of August 26, 2026.

    Those are the dates that matter for anyone tracking this, and they run in that order: the incident on August 26, the Vermont notification on September 8, the California notification on September 9, and the firm’s public statement on September 10. Nothing here is fresh as of this afternoon; what is new is that the regulatory record became legible this week.

    The Vermont Attorney General’s security breach notice database lists Greenberg Traurig, LLP with a report date of September 8, 2026, 10 Vermont residents affected, and the data element involved recorded as “Social Security Numbers.” Vermont does not publish the underlying consumer notice on the portal; it makes them available on request.

    The California Attorney General’s breach list carries the entry as “Greenberg Traurig, LLP (“GT”)” with a breach date of 08/26/2026 and a reported date of 09/09/2026. California’s threshold for appearing on that list is a notice sent to more than 500 California residents, so the California filing establishes a floor of 500 people in that state alone. A sample consumer notice is posted alongside the entry as a PDF; it could not be parsed by automated fetching, and its contents are therefore not reported here.

    Separately, on September 10, 2026, the firm made a public statement. It was given to Reuters and reached us through a secondary brief rather than from the firm directly, so it is reported here as relayed, not as read at first hand: the firm is described as saying that “an unauthorized actor” accessed documents and posted them on the dark web, that its “firm systems were not compromised or breached,” and that a “limited number of documents” and a “small number of affected clients” were involved. We could not read Reuters’ report or a statement on the firm’s own site.

    What the filings settle and what they do not

    Two things are established by primary record. First, Social Security numbers are in scope — that is Vermont’s own categorization on its portal, not a characterization by anyone reporting on the incident. Second, the population is not trivially small: California’s 500-resident threshold is a floor for one state, and ten Vermonters were notified in a state of roughly 650,000 people.

    Almost everything else is open. No total count of affected individuals appears in either filing. No discovery date is published. Neither portal states how the data was taken. And the firm’s own characterization — systems not compromised, documents nonetheless accessed and posted — points at some path that the firm has not described in anything we could read. A vendor, a third-party platform, a service the firm uses, an individual account: those are the ordinary candidates, and we are not going to pick one. It is worth being explicit that “our systems were not breached” and “client documents were taken and published” are not contradictory statements. They are, together, an incomplete one.

    We are also not going to attach an attacker to this. Ransomware leak-site trackers list the firm, and a claimed group name is circulating. No named victim, regulator, or filing we read attributes the incident to anyone, and this publication does not state attribution as fact.

    Why it matters

    The most useful thing about this incident is the order in which it became public. The firm’s public statement landed on September 10. The Vermont filing predates it by two days and the California filing by one, and the filings carry harder information than the statement does — a data element, a resident count, a breach date. A reader who followed only the coverage learned that the exposure was “limited.” A reader who checked two state portals learned that Social Security numbers were involved and that more than 500 Californians were notified.

    That gap is structural, not a criticism of any particular firm. A public statement is written to characterize; a state breach filing is written to satisfy a statutory disclosure form with fields for dates, counts, and data categories. The form is the part that does not compress. State attorney general portals are among the few primary sources in this field that are searchable, dated, and free, and they are checked far less often than vendor advisories are.

    The second thing worth drawing out is what a law firm’s breach means downstream, because it is not the firm’s own risk that is interesting. A firm of this size holds other organizations’ material — deal documents, litigation files, privileged communications, regulatory correspondence, and the personal data of its clients’ employees and customers. “A small number of affected clients” can be an accurate description of a compromise that is large for each of the clients involved. The unit of harm is not the law firm; it is the client whose file was in the set. Companies that received no notification because they are not the firm’s clients may still have people in those documents — opposing parties, witnesses, employees named in a matter.

    The third is the Social Security number detail, which changes what a reasonable response looks like. Document exposure without identifiers is a confidentiality problem. Document exposure with Social Security numbers is an identity-theft problem with a much longer tail, because the identifier does not rotate. Vermont’s portal records that element for this incident, which means the notification letters in at least one state told people their Social Security number was involved.

    What to do

    There is nothing to patch. The actions here are about finding out whether you are in scope.

    If your organization uses Greenberg Traurig, ask the firm directly whether your matters are in the affected set rather than waiting to be told. The firm has described the number of affected clients as small; that is a reason to ask, not a reason to assume you are outside it. Ask specifically what categories of your data were in the exposed documents, and whether any of your employees’ or customers’ personal data was in them.

    If you receive a notification letter, it will say which of your data elements were involved. Where a Social Security number is named, a credit freeze at all three bureaus is the response that actually matters, and it is free.

    If you maintain a third-party risk register, outside counsel belongs in it. Law firms are frequently omitted from vendor inventories because they are engaged by the legal department rather than procurement, and they routinely hold more sensitive material than the SaaS vendors that do get tracked. This incident is a reasonable prompt to check whether your register has one.

    If you monitor breaches as a practice, add the California and Vermont portals to what you check. Both carried this incident before it was widely reported, and both carry incidents that are never reported at all.

    Sourcing note

    The Vermont Attorney General’s security breach notice listing and the California Attorney General’s data breach list were both read directly. Vermont is the source for the September 8, 2026 report date, the count of 10 Vermont residents, and the “Social Security Numbers” data element. California is the source for the entry name “Greenberg Traurig, LLP (“GT”),” the August 26, 2026 breach date, and the September 9, 2026 reported date, and for the fact that a sample consumer notice is posted. That notice is a PDF and could not be parsed by automated fetching, so nothing from its text is reported here — it is the document most likely to answer the open questions below, and it is publicly available to anyone who can open it.

    The firm’s public statement of September 10, 2026 was not read at first hand. It was given to Reuters, and reached this story through a secondary brief summarizing that report. The quoted fragments — “an unauthorized actor,” “firm systems were not compromised or breached,” “limited number of documents,” “small number of affected clients” — are therefore reported as relayed and should be treated as weaker than the filing data above. Neither Reuters’ report nor a statement on the firm’s own website was reachable. The figure of more than 3,200 attorneys is the firm’s generally published size and is not drawn from any filing.

    Unresolved: the total number of individuals affected across all states, the discovery date, the mechanism by which documents were obtained given the firm’s statement that its systems were not compromised, whether any client organizations have been named, and whether additional state filings exist beyond Vermont and California. No attribution is asserted. Leak-site listings and claimed actor names were not treated as evidence and are not repeated here.

  • Nutex Health’s stolen data has been published online, and the update goes back under Item 8.01 with the materiality finding unchanged

    Nutex Health’s stolen data has been published online, and the update goes back under Item 8.01 with the materiality finding unchanged

    Eleven days after moving its breach disclosure up to Item 1.05, Nutex Health filed the update that the data is public under Item 8.01 — and said its assessment of materiality has not changed.

    What happened

    Nutex Health Inc. (NASDAQ: NUTX), a Houston company that operates 28 hospitals across 12 states, issued a press release on September 10, 2026, headed “NUTEX HEALTH PROVIDES UPDATE REGARDING CYBERSECURITY EVENT.” It was furnished to the SEC as an exhibit to an 8-K that EDGAR accepted at 5:53 p.m. ET on September 10 and dated September 11, 2026. The filing is accession 0001628280-26-061432, and it lands under Item 8.01, Other Events, together with Item 9.01.

    The substance of the update is that the stolen data is now public. In the company’s words: “The unauthorized third party has published on its website the data that was allegedly obtained.” Nutex is not yet willing to say the published material is genuinely its own. It says it is, “together with its cybersecurity experts and advisors, in the process of downloading, processing and analyzing the data” in order “to determine its contents, scope, and authenticity,” and that “due to the volume of data involved, the Company expects this process and review to take several weeks.”

    On the question the item heading raises, the release is explicit: “Based on the information currently available, the Company’s assessment of the materiality of this event, as set forth in the August 31, 2026 8-K, has not changed.”

    On notification: “The Company intends to make all required notifications based on its findings, including to impacted patients and employees.” On litigation: “Several purported class action complaints were filed against the Company in the United States District Court for the Southern District of Texas, Houston Division.” Law enforcement has been notified; no agency is named.

    What the release does not contain is as notable as what it does. There is no count of affected individuals, no volume of data, no date for the intrusion, and no date for the publication. The unauthorized third party is not named, and neither is the site the data was published on.

    The filing path so far

    This is the third 8-K Nutex has filed on this incident, and the item headings have moved twice.

    On August 24, 2026 (accession 0001628280-26-058606), Nutex disclosed under Item 8.01 that unauthorized activity had accessed and exfiltrated information from its servers, and stated that it “does not believe that the unauthorized access has had, or is reasonably likely to have, a material impact” on its business.

    On August 31, 2026 (accession 0001628280-26-059602), it refiled the same incident under Item 1.05, Material Cybersecurity Incidents — the heading the SEC reserves for incidents a registrant has determined to be material — while keeping the no-material-impact language. Severity Daily covered that filing in Nutex Health moved its breach disclosure to Item 1.05 seven days after filing it under 8.01.

    The September 10 update goes back to Item 8.01. It is a fresh 8-K, not an 8-K/A amending the Item 1.05 filing, and it does not restate or withdraw the materiality determination it points back to. It says that determination has not changed.

    Why it matters

    Item 1.05 is not a severity label. It is a disclosure trigger with a four-business-day clock attached, and it fires on a registrant’s determination that an incident is material. Item 8.01 is the catch-all for anything a company chooses to disclose. The SEC’s own guidance has been consistent that a company should not file under 1.05 unless it has made the materiality determination, precisely so that the heading keeps meaning something — and the practical consequence is that a great deal of downstream machinery reads the item number as the signal.

    That machinery now has a problem with this company. Anything keying on item headings sees a registrant that escalated to the material-incident heading on August 31 and then filed the development that most obviously bears on materiality — the data is out, and plaintiffs are lining up — under the heading for other events, with an express statement that nothing about the materiality picture has moved.

    It is worth being precise about what is and is not odd here. Filing an update under 8.01 is not itself improper; registrants do it routinely, and an amendment is required only where the original filing was materially deficient. A materiality determination that does not change is likewise a legitimate position: publication of exfiltrated data is not automatically material to a hospital operator’s financial condition, and the company may well be right. What is unusual is the combination — the heading moving up, then back down, with the same “no material impact” finding carried through all three filings, and no explanation in any of them for why the heading moved in the first place.

    Severity Daily has now written this shape three times in as many weeks. Park Dental Partners filed under Item 1.05 and then said it had found no material impact. NovoCure disclosed under 8.01 and wrote its own 1.05 trigger into the filing. Boston Scientific went the other way, escalating to 1.05 with a guidance cut and still saying nothing about data. The heading and the finding are drifting apart across filers, and Nutex is the clearest case yet because the same company has now used both headings for the same incident without saying what distinguishes them.

    The other thing to take from this filing is the authenticity language, which is the honest part of it. “Data that was allegedly obtained,” and a review to determine “contents, scope, and authenticity,” is the correct posture toward a leak-site dump that has not been verified. It is also a reminder of what nobody can tell you yet. The published set may be complete, partial, padded, or recycled. Until the review finishes — several weeks, by the company’s own estimate — any figure attached to this incident from outside the company is a claim about a dataset whose provenance the victim has not confirmed. If a record count appears in coverage of this breach before Nutex publishes one, it came from the party that published the data.

    What to do

    There is no patch here and no action item for most readers. What there is, for three specific audiences:

    If you are a Nutex patient or employee, the company says notifications will follow its review, and that review is expected to take several weeks. No notification has gone out yet, and no count exists. Nothing in the filing suggests waiting for a letter before placing a credit freeze.

    If you consume SEC filings programmatically — and a lot of vendor risk tooling now does — do not treat the item number as the materiality state. This incident has produced an 8.01, a 1.05, and another 8.01, with one unchanged determination underneath all three. Key on the text.

    If you are drafting your own disclosures, the gap Nutex leaves open is the one to close: when a heading changes, say in the filing what changed. Three filings in, an outside reader still cannot tell whether the August 31 escalation reflected a determination, an abundance of caution, or a correction.

    Sourcing note

    This story is written from the filing. The 8-K and its exhibit were read directly on EDGAR at accession 0001628280-26-061432 (CIK 0001479681). Submission type, item information, acceptance timestamp of 5:53 p.m. ET on September 10, 2026, filed-as-of date of September 11, 2026, and period of report of September 10, 2026 are taken from the filing’s index headers. All quoted language is from the exhibit, the press release dated September 10, 2026 from Houston.

    The August 24 and August 31 filings are identified by accession number from Severity Daily’s earlier reporting on them; the quoted “does not believe that the unauthorized access has had, or is reasonably likely to have, a material impact” is from the August 24 filing. The class action previously identified in that reporting is Haley v. Nutex Health, Inc., No. 4:26-cv-07197, filed August 27, 2026 in the Southern District of Texas; the September 10 release refers to “several purported class action complaints” in that district without docket numbers, and the individual dockets were not retrieved for this story.

    Unresolved: the number of individuals affected, the intrusion date, the publication date, the identity of the party that published the data, whether that data is authentic, and why the item heading moved from 8.01 to 1.05 and back. No regulator is named in the filing, and no HHS Office for Civil Rights entry was confirmed — the OCR breach portal is a dynamic application and is not retrievable by automated fetching, which is a standing gap in confirming affected counts for healthcare incidents.