Were you recently affected by a data breach?

Eckert Seamans Cherin & Mellott Data Breach

Eckert Seamans Cherin & Mellott, LLC, a Pittsburgh-based law firm, discovered that an unauthorized party accessed files containing clients’ personal information during a cybersecurity incident.

Eckert Seamans Cherin & Mellott
Date of Breach: Unauthorized access discovered on or about August 17, 2026, following an extensive forensic investigation
CAU logo

Who was affected:

Clients of Eckert Seamans Cherin & Mellott

Impacted Data:

Full name, in combination with other personal information not fully detailed in the company’s public notice

Eckert Seamans Cherin & Mellott, LLC, a full-service law firm headquartered in Pittsburgh, Pennsylvania, has notified individuals that a cybersecurity incident may have exposed personal information the firm acquired while providing legal services to one of its clients. Law firms routinely hold sensitive personal and case-related information belonging to people who are not their direct clients, and a breach at a firm like this can affect individuals who may never have had any direct relationship with the firm itself.

Eckert Seamans Cherin & Mellott’s Data Breach Investigation

According to a notice sent to affected individuals, Eckert Seamans Cherin & Mellott (‘ESCM’) detected a cybersecurity incident and states that upon discovery it contained the threat, immediately began a thorough investigation, and notified law enforcement. The firm says it worked closely with external cybersecurity professionals to determine whether personal or sensitive data was involved. After what it describes as an extensive forensic investigation and a comprehensive manual document review, ESCM discovered on August 17, 2026 that an unauthorized party had accessed or acquired files containing affected individuals’ personal information.

ESCM’s notice states that the affected files contained each individual’s full name in combination with other information, though the firm’s publicly filed notice does not spell out every additional data element involved. The firm says it has no knowledge that the exposed information has been or will be misused as a direct result of the incident, and it is offering complimentary credit monitoring, CyberScan monitoring, a $1,000,000 insurance reimbursement policy, and identity theft recovery services to those affected.

Because ESCM acquired the affected information in connection with providing legal services to one of its own clients, the individuals notified of this breach may include people who interacted with ESCM’s client rather than with the law firm directly. This is a recurring feature of law firm data breaches: the personal information a firm holds often extends well beyond its own client roster to include opposing parties, witnesses, employees of a client, or other individuals whose information became part of a legal matter the firm was handling.

Law firms have become an increasingly attractive target for cybercriminals in recent years, in part because they concentrate large volumes of confidential and sensitive information across many unrelated matters, often with fewer dedicated cybersecurity resources than the corporate clients they represent. A single compromised firm can expose personal data tied to numerous separate legal matters at once, which is part of why regulators and industry groups have pushed law firms to adopt stronger data security practices, including encryption, access controls, and faster breach detection capabilities.

The multi-month gap that can occur between an initial security incident and a firm’s completion of a comprehensive forensic review, as described in ESCM’s notice, is a common feature of law firm breaches specifically because a manual document review is often required to determine precisely which client matters and which individuals’ files were affected. Individuals who receive a notice like this one should take it seriously even though the firm reports no evidence of misuse to date, since exposed personal information can be held or used by criminals well after an initial notification is sent.

Manual document review, as ESCM describes undertaking here, is a labor-intensive process that typically involves attorneys or trained reviewers examining potentially affected files one by one to determine both what categories of personal information they contain and to whom that information belongs. For a firm handling many active and closed matters at once, this kind of review can take weeks or months even after outside forensic specialists have already identified which systems or accounts were compromised. This is one reason breach notifications tied to professional services firms, including law firms, accounting firms, and financial advisors, often arrive months after the underlying security incident itself, even when the firm acted promptly upon initial discovery.

Individuals affected by a law firm data breach sometimes assume, incorrectly, that because they were never a direct client of the firm, they have no standing to be concerned or to take action. In fact, personal information collected in connection with a legal matter, whether from a client, an opposing party, a witness, or an employee of a client, deserves the same protection as any other personal data, and individuals whose information was exposed in a firm’s possession may still have legal remedies available to them regardless of the nature of their original connection to the underlying matter.

When Did This Breach Occur?

Eckert Seamans Cherin & Mellott discovered that an unauthorized party had accessed or acquired files containing personal information on or about August 17, 2026, following an extensive forensic investigation and manual document review.

What Information Was Breached?

ESCM has stated that the affected files contained each individual’s full name in combination with other personal information. The firm’s public notice does not specify a complete, uniform list of every additional data element involved for all affected individuals.

What You Can Do

If you received a breach notification letter from Eckert Seamans Cherin & Mellott, consider taking the following steps:

  • Enroll in the complimentary credit monitoring and identity theft recovery services offered in the notification letter.
  • Place a fraud alert or security freeze on your credit files with Equifax, Experian, and TransUnion.
  • Regularly review your financial account statements and credit reports for unfamiliar activity.
  • Report any suspected identity theft to the FTC at identitytheft.gov and to local law enforcement.

File a Data Breach Lawsuit Against Eckert Seamans Cherin & Mellott

If you received a notice that your personal information was exposed in the Eckert Seamans Cherin & Mellott data breach, you may have legal options available to you. Law firms that collect and store sensitive personal information have a duty to protect it, and a breach like this one can leave affected individuals facing a long-term risk of identity theft and fraud.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 10, 2026
Date of Breach: Not publicly disclosed in the firm's notice
Date of Breach: Unauthorized access discovered on or about August 17, 2026, following an extensive forensic investigation
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.