Were you recently affected by a data breach?

Herbert Smith Freehills Kramer Data Breach

Herbert Smith Freehills Kramer LLP, a global law firm, reported a data breach to the Vermont Attorney General affecting 4 Vermont residents whose Social Security numbers, government ID numbers, and health records were exposed. Affected individuals should understand their rights and available protective steps.

Herbert Smith Freehills Kramer
Date of Breach: Reported to the Vermont Attorney General on July 29, 2026 (underlying breach date not publicly disclosed)
CAU logo

Who was affected:

Clients of Herbert Smith Freehills Kramer

Impacted Data:

Social Security numbers, government ID numbers, health records

Herbert Smith Freehills Kramer is a large global law firm formed through the 2025 combination of Herbert Smith Freehills and Kramer Levin Naftalis & Frankel. Vermont’s Attorney General was recently notified that a data breach exposed personal information belonging to some of the firm’s clients or contacts.

Law firms that collect and store Social Security numbers, government identification numbers, and health records have a responsibility to protect that information from unauthorized access, and to promptly notify anyone affected when a breach occurs.

Herbert Smith Freehills Kramer’s Data Breach Investigation

On July 29, 2026, Herbert Smith Freehills Kramer LLP reported a data breach to the Vermont Attorney General’s Office, disclosing that Social Security numbers, government ID numbers, and health records belonging to Vermont residents were compromised. The filing indicates that 4 Vermont residents were affected, and the incident was classified under the Other Commercial reporting category by the Vermont AGO. Vermont’s breach-notification program no longer publishes copies of the underlying consumer notification letters for reasons related to digital accessibility, so specific details about how the breach occurred, when it was first detected internally, and what remediation steps the firm has taken have not been made publicly available through the state’s own disclosure. Herbert Smith Freehills Kramer, commonly known as HSF Kramer, was formed when Herbert Smith Freehills, a major UK-based international law firm, combined with the US firm Kramer Levin Naftalis & Frankel, with the merger completing in mid-2025 to create a global legal practice with roughly 2,700 lawyers across 26 offices. As a large, multi-jurisdictional law firm, HSF Kramer holds highly sensitive personal, financial, and health-related information for a substantial number of clients, employees, and other individuals in the ordinary course of its legal practice.

Law firms have increasingly become attractive targets for cybercriminals because of the sheer volume and sensitivity of the information they hold on behalf of clients, including litigation files, medical records, financial documents, and government identification numbers that frequently pass through a firm’s systems during the course of representation. Because a law firm often serves as a central repository connecting many different clients’ most sensitive records, a single successful intrusion can expose personal information belonging to individuals who may have had no direct relationship with the attacker or even any reason to expect their data was held by the firm in the first place.

The combination of Social Security numbers, government ID numbers, and health records exposed in this incident is a particularly concerning mix from a fraud-risk perspective. Social Security numbers and government-issued ID numbers can be used together to open new lines of credit, file fraudulent tax returns, or create synthetic identities, while exposed health records can be used for medical identity theft, including fraudulently obtaining prescriptions or medical services in a victim’s name. Unlike a compromised password or credit card number, a Social Security number generally cannot be changed, meaning the risk created by its exposure can persist for years after the breach itself has been resolved.

State data breach notification laws, including Vermont’s own reporting requirements, exist to ensure that individuals learn promptly when their personal information has been compromised so they can take protective action. Reporting deadlines and required disclosures vary from state to state, but the underlying purpose is consistent: giving affected individuals the earliest possible opportunity to monitor their accounts, place fraud alerts, or freeze their credit before any stolen information can be misused by bad actors.

Anyone who receives a breach notification letter referencing this incident should also be alert to a secondary risk, since scammers often use news of a real breach as cover for follow-up phishing attempts. These scams frequently involve fake notification emails or text messages that impersonate the breached firm in an effort to trick recipients into providing even more personal or financial information. Recipients of any communication about this breach should verify its authenticity independently rather than clicking embedded links or calling phone numbers provided in an unsolicited message.

When Did This Breach Occur?

Herbert Smith Freehills Kramer reported this breach to the Vermont Attorney General’s Office on July 29, 2026. The Vermont AGO’s public disclosure table lists only the date the report was received and does not include the date the underlying unauthorized access actually occurred, when it was first detected internally, or when notification letters were sent to affected individuals. Vermont discontinued posting the underlying consumer notification letters that would typically supply that additional detail, citing digital accessibility requirements for government websites, so those specific dates are not currently available from any public source. As more information becomes available, this page will be updated to reflect the confirmed breach and detection dates.

What Information Was Breached?

According to the firm’s filing with the Vermont Attorney General, the personal information involved in this breach included Social Security numbers, government identification numbers, and health records belonging to affected Vermont residents. The filing does not specify additional detail, such as which particular health information was exposed or whether financial account information was also involved, and Vermont’s disclosure table lists only the broad categories of data reported for this incident. Because this combination of data is highly sensitive, even a breach affecting a small number of individuals, as reported here, can create a serious risk of identity theft, financial fraud, and medical identity theft for the 4 individuals identified in the filing. Anyone who received or later receives a formal notification letter from Herbert Smith Freehills Kramer should review it carefully, as it may identify additional data categories specific to their own individual record.

What You Can Do

If you were notified that your information was involved in this breach, there are several steps you can take to help protect yourself:

  • Carefully review any notification letter you receive from Herbert Smith Freehills Kramer for specific instructions and any complimentary credit monitoring or identity protection services offered.
  • Place a fraud alert or credit freeze with the three major credit bureaus, Equifax, Experian, and TransUnion, to make it harder for anyone to open new accounts in your name.
  • Monitor your bank and credit card statements, as well as your credit reports and any explanation-of-benefits statements from your health insurer, for any unfamiliar activity.
  • Be cautious of unsolicited phone calls, emails, or text messages referencing this breach, and never provide personal information in response to a message you did not initiate.
  • Consider filing your taxes early, since a stolen Social Security number can be used to file a fraudulent tax return in your name.

File a Data Breach Lawsuit Against Herbert Smith Freehills Kramer

If you were affected by this breach, you may have legal options available to you. Individuals whose Social Security numbers, government ID numbers, or health records are exposed due to a company’s failure to reasonably secure them may be entitled to pursue compensation through a data breach lawsuit.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to the Vermont Attorney General on August 25, 2026
Date of Breach: Reported to the Vermont Attorney General on August 26, 2026
Date of Breach: Reported to the Vermont Attorney General on August 26, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.