Herbert Smith Freehills Kramer is a large global law firm formed through the 2025 combination of Herbert Smith Freehills and Kramer Levin Naftalis & Frankel. Vermont’s Attorney General was recently notified that a data breach exposed personal information belonging to some of the firm’s clients or contacts.
Law firms that collect and store Social Security numbers, government identification numbers, and health records have a responsibility to protect that information from unauthorized access, and to promptly notify anyone affected when a breach occurs.
Herbert Smith Freehills Kramer’s Data Breach Investigation
On July 29, 2026, Herbert Smith Freehills Kramer LLP reported a data breach to the Vermont Attorney General’s Office, disclosing that Social Security numbers, government ID numbers, and health records belonging to Vermont residents were compromised. The filing indicates that 4 Vermont residents were affected, and the incident was classified under the Other Commercial reporting category by the Vermont AGO. Vermont’s breach-notification program no longer publishes copies of the underlying consumer notification letters for reasons related to digital accessibility, so specific details about how the breach occurred, when it was first detected internally, and what remediation steps the firm has taken have not been made publicly available through the state’s own disclosure. Herbert Smith Freehills Kramer, commonly known as HSF Kramer, was formed when Herbert Smith Freehills, a major UK-based international law firm, combined with the US firm Kramer Levin Naftalis & Frankel, with the merger completing in mid-2025 to create a global legal practice with roughly 2,700 lawyers across 26 offices. As a large, multi-jurisdictional law firm, HSF Kramer holds highly sensitive personal, financial, and health-related information for a substantial number of clients, employees, and other individuals in the ordinary course of its legal practice.
Law firms have increasingly become attractive targets for cybercriminals because of the sheer volume and sensitivity of the information they hold on behalf of clients, including litigation files, medical records, financial documents, and government identification numbers that frequently pass through a firm’s systems during the course of representation. Because a law firm often serves as a central repository connecting many different clients’ most sensitive records, a single successful intrusion can expose personal information belonging to individuals who may have had no direct relationship with the attacker or even any reason to expect their data was held by the firm in the first place.
The combination of Social Security numbers, government ID numbers, and health records exposed in this incident is a particularly concerning mix from a fraud-risk perspective. Social Security numbers and government-issued ID numbers can be used together to open new lines of credit, file fraudulent tax returns, or create synthetic identities, while exposed health records can be used for medical identity theft, including fraudulently obtaining prescriptions or medical services in a victim’s name. Unlike a compromised password or credit card number, a Social Security number generally cannot be changed, meaning the risk created by its exposure can persist for years after the breach itself has been resolved.
State data breach notification laws, including Vermont’s own reporting requirements, exist to ensure that individuals learn promptly when their personal information has been compromised so they can take protective action. Reporting deadlines and required disclosures vary from state to state, but the underlying purpose is consistent: giving affected individuals the earliest possible opportunity to monitor their accounts, place fraud alerts, or freeze their credit before any stolen information can be misused by bad actors.
Anyone who receives a breach notification letter referencing this incident should also be alert to a secondary risk, since scammers often use news of a real breach as cover for follow-up phishing attempts. These scams frequently involve fake notification emails or text messages that impersonate the breached firm in an effort to trick recipients into providing even more personal or financial information. Recipients of any communication about this breach should verify its authenticity independently rather than clicking embedded links or calling phone numbers provided in an unsolicited message.
When Did This Breach Occur?
Herbert Smith Freehills Kramer reported this breach to the Vermont Attorney General’s Office on July 29, 2026. The Vermont AGO’s public disclosure table lists only the date the report was received and does not include the date the underlying unauthorized access actually occurred, when it was first detected internally, or when notification letters were sent to affected individuals. Vermont discontinued posting the underlying consumer notification letters that would typically supply that additional detail, citing digital accessibility requirements for government websites, so those specific dates are not currently available from any public source. As more information becomes available, this page will be updated to reflect the confirmed breach and detection dates.
What Information Was Breached?
According to the firm’s filing with the Vermont Attorney General, the personal information involved in this breach included Social Security numbers, government identification numbers, and health records belonging to affected Vermont residents. The filing does not specify additional detail, such as which particular health information was exposed or whether financial account information was also involved, and Vermont’s disclosure table lists only the broad categories of data reported for this incident. Because this combination of data is highly sensitive, even a breach affecting a small number of individuals, as reported here, can create a serious risk of identity theft, financial fraud, and medical identity theft for the 4 individuals identified in the filing. Anyone who received or later receives a formal notification letter from Herbert Smith Freehills Kramer should review it carefully, as it may identify additional data categories specific to their own individual record.
What You Can Do
If you were notified that your information was involved in this breach, there are several steps you can take to help protect yourself:
- Carefully review any notification letter you receive from Herbert Smith Freehills Kramer for specific instructions and any complimentary credit monitoring or identity protection services offered.
- Place a fraud alert or credit freeze with the three major credit bureaus, Equifax, Experian, and TransUnion, to make it harder for anyone to open new accounts in your name.
- Monitor your bank and credit card statements, as well as your credit reports and any explanation-of-benefits statements from your health insurer, for any unfamiliar activity.
- Be cautious of unsolicited phone calls, emails, or text messages referencing this breach, and never provide personal information in response to a message you did not initiate.
- Consider filing your taxes early, since a stolen Social Security number can be used to file a fraudulent tax return in your name.
File a Data Breach Lawsuit Against Herbert Smith Freehills Kramer
If you were affected by this breach, you may have legal options available to you. Individuals whose Social Security numbers, government ID numbers, or health records are exposed due to a company’s failure to reasonably secure them may be entitled to pursue compensation through a data breach lawsuit.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.