Were you recently affected by a data breach?

Fragomen Data Breach

Fragomen began notifying people in October 2026 that an unauthorized party gained remote access to a user account in a social engineering campaign and copied a subset of files containing personal information.

Fragomen
Date of Breach: May 5, 2026
CAU logo

Who was affected:

Clients of Fragomen

Impacted Data:

Names and other personal data elements not itemized in the filed notice

Fragomen, formally Fragomen, Del Rey, Bernsen & Loewy, LLP, has begun notifying people that an unauthorized party gained remote access to a user account at the firm and copied a subset of files. The notice letters are dated October 2, 2026.

A global immigration services firm collects passport details, identity records, employment histories, and family information as a matter of routine. Companies that handle information this sensitive have a responsibility to protect it, and people whose records were exposed deserve straight answers.

Fragomen’s Data Breach Investigation

Fragomen describes itself in its notice as a global immigration services firm. Its notification letter, filed as a sample with the California Attorney General and dated October 2, 2026, explains that the firm learned on May 5, 2026, that an unauthorized third party had gained remote access to a single user account. The firm says it determined the access was part of a social engineering campaign, meaning the intruder relied on deception aimed at a person rather than on breaking through technical defenses.

According to the notice, the firm acted to contain the incident promptly once it was discovered. It reports that it brought in outside cybersecurity experts and notified law enforcement. The investigation ultimately concluded that the unauthorized party accessed and copied a subset of files. Fragomen then began a comprehensive review of the data involved so that it could identify each individual whose personal information may have been contained in those files.

That review concluded that some of the recipient’s personal information was in the affected files. The letter states that the information includes the person’s name along with additional data elements. In the sample letter filed with regulators, the field that should list those additional elements was left as an unfilled template placeholder, so the specific categories exposed have not been made public through this filing. The categories may vary from person to person, and the firm has not published a total number of people affected.

As a response, the firm says it has put additional security measures in place designed to strengthen its systems and data, and that it continues to evaluate further steps. It is offering a complimentary 24-month membership of Experian IdentityWorks, which it describes as a product that helps detect possible misuse of personal information and supports identity theft resolution. The enrollment deadline listed in the letter is January 29, 2027. A call center is available at 833-931-4744 on weekdays from 9 a.m. to 9 p.m. Eastern. The firm states that it is not aware of any evidence that personal information has been or will be misused.

Social engineering has become one of the most common ways organizations lose control of sensitive files. An attacker may impersonate a help desk worker, a colleague, or a vendor, and persuade a person to grant remote access or hand over a login. Once inside a legitimate account, the intruder can browse and copy whatever that account is permitted to see, and standard security tools may treat the activity as normal. Firms that serve international clients and employers are attractive targets because their files tend to combine identity documents with employment and family details in a single place.

For someone receiving a letter, the practical question is how much the exposed combination of information could enable. Names paired with government identification numbers, dates of birth, or immigration-related records can support identity theft, fraudulent applications for credit, and convincing phishing messages that reference real details of a person’s life. Because the filed sample does not itemize the data, a careful reading of the individual letter, which should specify what applied, is the most reliable starting point for judging personal risk.

Prompt notification matters in an incident like this because the window between a theft of files and the moment affected people learn about it is when stolen information is most likely to be put to use. State breach notification laws generally require organizations to tell residents without unreasonable delay once the scope of an incident is understood, and several states set outer deadlines measured in days or weeks. Here the firm identified the access in May and sent letters in October, a gap that reflects the time it says it needed to review the copied files. How that timeline compares with what the law requires in each affected person’s home state is another question that may be examined.

Questions about whether the firm’s access controls, employee training, and monitoring were adequate before May 2026 are the kind that regulators and courts can examine. This page will be updated if additional information about the scope of the incident becomes public.

When Did This Breach Occur?

Fragomen states that it learned of the unauthorized remote access to a user account on May 5, 2026. The notice does not say how long before that date the access began.

The firm then reviewed the affected files to identify whose information they contained, a process that took several months. Notification letters are dated October 2, 2026, and the sample notice was posted by the California Attorney General’s office shortly after. The Experian IdentityWorks enrollment deadline is January 29, 2027.

What Information Was Breached?

The notice says the personal information involved includes each recipient’s name along with other data elements. The sample letter filed with the California Attorney General leaves the list of additional elements as an unfilled placeholder, so the exact categories have not been publicly itemized and may differ by person.

Because the files came from an immigration services firm, records of this type can include identity and travel documents, dates of birth, and government ID numbers. That is general context about the kind of work the firm does and not a confirmed list for this incident. Your own notice letter is the best source for what applied to you.

What You Can Do

If you received a notice from Fragomen, consider these steps:

  • Enroll in the complimentary 24-month Experian IdentityWorks membership before the January 29, 2027 deadline.
  • Review bank and card statements and your free credit reports for activity you do not recognize.
  • Consider a fraud alert or a free security freeze with Equifax, Experian, and TransUnion.
  • Be wary of unexpected emails, calls, or texts that mention your immigration matter, employer, or the firm.
  • Keep your letter and record any suspicious activity along with the date.

File a Data Breach Lawsuit Against Fragomen

When a firm that handles sensitive identity and immigration records loses control of files, the people affected may have legal options. A data breach class action can let many affected individuals pursue accountability together, including recovery for time spent, out-of-pocket costs, and the lasting risk created by the exposure of their information.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: May 5, 2026
Date of Breach: August 31, 2026
Date of Breach: Reported to the Texas Attorney General on October 2, 2026; incident date not disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.