Buist Byars & Taylor LLC, a South Carolina-based law firm with offices in the Mount Pleasant and North Charleston area, has reported a data security incident to the Vermont Attorney General’s Office. The filing indicates that sensitive personal information belonging to at least some Vermont residents connected to the firm may have been exposed.
Law firms routinely hold highly sensitive client records, including financial account information, government identification numbers, and health information tied to litigation or transactional matters. When that data is compromised, the consequences for affected individuals can be significant and long-lasting.
Buist Byars & Taylor’s Data Breach Investigation
According to a notice filed with the Vermont Attorney General’s Office on August 11, 2026, Buist Byars & Taylor LLC disclosed a data security incident affecting at least two Vermont residents. The filing categorizes the firm’s business as “Other Commercial” and lists a range of sensitive data types as compromised, including Social Security numbers, government-issued identification numbers, financial account codes, credit and debit account information, and health records.
The Vermont Attorney General’s Office no longer publishes the underlying breach notification letters or documents filed by companies, citing digital accessibility requirements for government websites. As a result, the specific cause of the incident, the exact number of individuals affected nationwide, and the precise dates the breach occurred and was discovered have not been made publicly available beyond the summary filing itself.
Law firms have increasingly become targets for cybercriminals because of the depth and sensitivity of the records they retain on behalf of clients. A single firm’s case files can include Social Security numbers, medical histories, banking details, and other information that is highly valuable on the black market and useful for identity theft or fraud. Breaches at legal and financial services firms have become more frequent in recent years as attackers recognize that professional service providers often serve as a single point of entry to a large volume of sensitive third-party data.
The combination of data types reportedly involved in this incident is particularly concerning. Social Security numbers and government-issued ID numbers can be used to open new credit lines or file fraudulent tax returns in a victim’s name. Financial account codes and credit or debit account information can enable direct unauthorized transactions. Health records, meanwhile, can be exploited for medical identity theft or used in targeted phishing schemes that reference a person’s actual medical history to appear more convincing.
Under state data breach notification laws, including Vermont’s Security Breach Notice Act, companies that experience a breach involving residents’ personal information are generally required to notify affected individuals and, in many cases, the state attorney general’s office within a defined timeframe. Filings like this one are part of that regulatory process, even when, as here, the full underlying notice is not made public.
When Did This Breach Occur?
The exact date the breach occurred and the date it was discovered have not been publicly disclosed. What is known is that Buist Byars & Taylor LLC filed its notification with the Vermont Attorney General’s Office on August 11, 2026. Multi-state breach notification filings often occur weeks or months after a breach is first discovered, as companies investigate the scope of an incident, determine which individuals and states are affected, and prepare the required notices before filing with each relevant regulator.
What Information Was Breached?
Based on the Vermont Attorney General’s filing, the following categories of personal information may have been compromised in this incident: Social Security numbers, government-issued identification numbers, financial account codes, credit and debit card account information, and health records. The filing does not specify how many individuals nationwide were affected beyond the two Vermont residents identified in the state’s summary, nor does it disclose the specific cause of the breach.
What You Can Do
If you have received a notice from Buist Byars & Taylor LLC, or believe you may have been affected by this incident, consider taking the following steps:
- Review your financial account and credit card statements closely for any unauthorized activity.
- Place a fraud alert or security freeze on your credit files with the three major credit bureaus.
- Monitor your credit reports regularly for unfamiliar accounts or inquiries.
- Be cautious of unsolicited calls, emails, or texts referencing this breach, your medical history, or your financial accounts, as scammers often use breach news to run phishing schemes.
- Consider enrolling in any credit monitoring or identity protection services offered by the company, if available.
File a Data Breach Lawsuit Against Buist Byars & Taylor
If your personal information was exposed in the Buist Byars & Taylor LLC data breach, you may have legal options available to help recover losses tied to identity theft, fraud, or the time and expense of protecting yourself going forward.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.