St. Peter O’Brien Law Offices, a Missoula, Montana law firm, has notified individuals that unauthorized activity on its computer network may have exposed information connected to legal services the firm provided. Law firms hold uniquely sensitive information about the people they represent, and any confirmed intrusion into that data warrants a serious, thorough response.
Firms entrusted with personal and legal information have a responsibility to protect it from unauthorized access, and to promptly and clearly inform affected individuals when that protection fails.
St. Peter O’Brien Law Offices’s Data Breach Investigation
According to a notification letter sent to affected individuals, St. Peter O’Brien Law Offices identified suspicious activity on its computer network and engaged third-party computer forensic specialists to investigate. The firm’s investigation determined that certain information within its network may have been accessed or downloaded without authorization between September 19, 2025 and September 23, 2025. After the scope of the activity was confirmed, the firm conducted a review of the affected information to determine what data was involved and who it related to, a process the firm says was completed on April 10, 2026. Notification letters to affected individuals went out April 23, 2026, roughly seven months after the unauthorized access window and about two weeks after the review concluded.
The letter describes the exposed information only as material “collected in connection with the provision of legal services” the firm provided, along with the individual’s name, without publicly specifying every category of data involved. This kind of limited disclosure is common in the immediate aftermath of a law firm data breach: firms often owe overlapping duties to former and current clients, including attorney-client privilege and confidentiality obligations, that can shape how much detail about the underlying legal matters gets included in a breach notice, even when the notice itself is otherwise thorough.
Law firms have increasingly become attractive targets for cybercriminals precisely because of the concentrated, sensitive information they hold on behalf of clients, ranging from litigation records and financial details to personal identifiers gathered during representation. Unlike a retailer or a healthcare provider, a law firm’s files can tie an individual’s name directly to a specific legal proceeding, dispute, or personal matter, information that can be considerably more sensitive in the wrong hands than a standalone data point like a credit card number. That combination makes law firm breaches a distinct category of concern, even when the number of confirmed data elements disclosed publicly is limited.
The roughly seven-month gap between the September 2025 unauthorized access window and the April 2026 notification date is not unusual for incidents of this kind. Determining that a network intrusion occurred, containing it, retaining forensic specialists, and then working through which specific individuals and records were actually implicated is a multi-step process that regulatory notification laws generally accommodate, provided the investigation proceeds diligently and notification follows once the scope is reasonably understood. Montana law, like most states, requires notification without unreasonable delay once an investigation is complete.
Individuals who receive a breach notification letter from a law firm should treat it seriously even when the listed data categories seem limited, since a firm’s own files may contain considerably more context about a person’s legal history than the notice itself discloses. Anyone who worked with St. Peter O’Brien Law Offices, or whose information may have passed through the firm in connection with a legal matter, should review the notification carefully and take the protective steps outlined below.
Even when a breach notice lists only a name as the confirmed exposed data point, the surrounding context matters. A name tied to a specific law firm’s files can reveal, by implication, that a person was involved in a particular type of legal matter, whether estate planning, a business dispute, adoption, or another sensitive proceeding. That kind of inference is not something identity thieves typically target directly, but it can still be exploited in social engineering schemes, where a scammer references real details about a person’s legal history to appear credible when requesting money, account access, or additional personal information over phone or email.
Notification timelines like the one described here, several months between the confirmed unauthorized access and the point individuals are actually told about it, are a routine part of how data breach investigations unfold, not evidence of wrongdoing on their own. Forensic firms typically need weeks to determine what systems were accessed, and additional time to map which specific files or records were involved and identify the people connected to them. Regulators generally expect notification once that process is reasonably complete rather than immediately upon discovery of suspicious activity, which is why the gap between incident and notice is common across law firm and professional-services breaches generally.
When Did This Breach Occur?
The firm states that unauthorized access to its network occurred between September 19, 2025 and September 23, 2025. The firm’s review of the scope of that access was completed April 10, 2026, and affected individuals were notified by letter dated April 23, 2026.
What Information Was Breached?
St. Peter O’Brien Law Offices’ notification letter identifies the affected individual’s name, along with information collected in connection with the legal services the firm provided, as involved in the incident. The firm has not publicly detailed additional specific categories of data beyond this.
What You Can Do
St. Peter O’Brien Law Offices is offering affected individuals 12 months of complimentary credit monitoring and identity theft protection services through Cyberscout, a TransUnion company. Affected individuals should also consider the following steps:
- Enroll in the complimentary credit monitoring offered in the notification letter before the enrollment deadline
- Review credit reports and account statements regularly for unfamiliar activity
- Consider placing a fraud alert or credit freeze with the three major credit bureaus
- Remain alert to unexpected calls, emails, or letters referencing the firm or your legal matter, which can be used in follow-up phishing attempts
File a Data Breach Lawsuit Against St. Peter O’Brien Law Offices
If you received a notification letter from St. Peter O’Brien Law Offices, or believe your information may have been involved in this incident, you may have legal options. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.