Abramson, Brown & Dugan, a Manchester, New Hampshire-based personal injury and medical malpractice law firm, has reported a data security incident to the Vermont Attorney General’s Office affecting individuals whose sensitive personal information may have been exposed. Companies and law firms that collect and store Social Security numbers and government-issued identification numbers carry a legal responsibility to keep that information secure, and a failure to do so can expose affected individuals to serious risks of identity theft and fraud.
Abramson, Brown & Dugan’s Data Breach Investigation
According to a notice filed with the Vermont Attorney General’s Office, Abramson, Brown & Dugan reported a data security incident affecting 71 Vermont residents. The filing indicates that the exposed information included Social Security numbers and government-issued ID numbers, some of the most sensitive categories of personal data because of how directly they can be used to open fraudulent accounts, file false tax returns, or otherwise impersonate a victim.
Law firms are increasingly attractive targets for cybercriminals. Firms that handle personal injury and medical malpractice cases routinely collect and retain highly sensitive client records, including medical histories, insurance information, and government-issued identification, often for years after a case concludes. That combination of sensitive data and long retention periods makes law firm systems a valuable target, and the legal industry as a whole has seen a marked increase in reported data security incidents in recent years as firms manage growing volumes of digital client records.
When Social Security numbers and government ID numbers are exposed together, the risk to victims is compounded. Unlike a compromised credit card number, which can be canceled and reissued, a Social Security number is effectively permanent, and once exposed it can be used for years afterward to open new lines of credit, file fraudulent unemployment or tax claims, or pass identity verification checks at financial institutions. Government-issued ID numbers, such as a driver’s license number, add another layer of risk, since the two data points together are often sufficient to pass many identity verification processes without additional documentation.
State data breach notification laws, including Vermont’s, generally require companies to notify affected residents and the state Attorney General’s Office within a defined window after discovering an incident, though the specific circumstances, cause, and discovery date of this particular incident have not been made public as of this writing. Firms are typically required to disclose the categories of information involved and the number of residents affected, even when other investigative details remain confidential while the incident is still being assessed.
Affected individuals should treat any notification letter from Abramson, Brown & Dugan seriously and take the protective steps outlined below as soon as possible, since the earlier identity-theft protections are put in place, the better positioned a person is to catch and limit any fraudulent activity connected to this incident.
When Did This Breach Occur?
The exact date the incident occurred and the date it was discovered have not been publicly disclosed. Abramson, Brown & Dugan reported the incident to the Vermont Attorney General’s Office, with the filing indicating the breach affected 71 Vermont residents. As more information becomes available, this page will be updated.
What Information Was Breached?
Based on the notification filed with the Vermont Attorney General’s Office, the exposed information included Social Security numbers and government-issued ID numbers. Abramson, Brown & Dugan has not publicly disclosed additional details about the specific circumstances of the incident, such as its cause or how the affected data was accessed.
What You Can Do
If you received a notification letter from Abramson, Brown & Dugan or believe you may have been affected, consider taking the following steps:
- Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion)
- Monitor your credit reports and financial account statements closely for unfamiliar activity
- Consider enrolling in any credit monitoring or identity protection services offered in the notification letter
- Be cautious of follow-up phishing emails, calls, or texts referencing this breach, since scammers often use news of a breach to target victims a second time
- File an identity theft report with the FTC at IdentityTheft.gov if you notice signs of fraud
File a Data Breach Lawsuit Against Abramson, Brown & Dugan
If you were notified that your personal information was exposed in the Abramson, Brown & Dugan data breach, you may be entitled to compensation. Companies and firms that fail to adequately protect sensitive personal data can be held legally accountable for the resulting harm to affected individuals.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.