Midkiff, Muncie & Ross, P.C. (MMR), a Virginia-based law firm, has notified individuals that a data security incident may have exposed their personal information. The firm detected unusual activity on its network months before the full scope of the incident was confirmed, and a subsequent review determined that sensitive personal and financial details had likely been accessed by an unauthorized party. Companies and law firms that store sensitive client records carry a legal and ethical responsibility to safeguard that information, and when a breach occurs, the people whose data was exposed deserve a clear explanation of what happened and what protections are available to them.
Midkiff, Muncie & Ross, P.C.’s Data Breach Investigation
According to notice provided by MMR, the firm first became aware of unusual activity disrupting access to certain IT systems within its network on December 8, 2025. After detecting and containing the incident, MMR retained outside cybersecurity experts to investigate the scope of what had occurred and to determine whether any data had been affected. That investigation determined that an unknown actor had potentially acquired certain files from the firm’s network. Because identifying exactly whose information was contained in those files required a comprehensive manual review, MMR reported that it did not confirm the full scope of the impact and secure information sufficient to notify affected individuals until August 18, 2026, more than eight months after the initial detection.
Law firms are frequent targets for cybercriminals precisely because of the volume and sensitivity of the records they retain on behalf of clients, ranging from litigation files to insurance, medical, and financial documentation. A single firm’s case files can span years of a client’s most sensitive personal history, making a law firm network breach potentially far more damaging than a breach limited to a single transaction or account. The combination of data types MMR has acknowledged, including Social Security numbers, government-issued identification numbers, and medical and financial information, is especially valuable to identity thieves because it can be used to open new credit accounts, file fraudulent tax returns, or impersonate victims in dealings with government agencies and insurers.
The multi-month gap between MMR’s initial detection of the intrusion and its confirmation of which individuals were affected is not unusual in incidents involving large volumes of unstructured files, but it does mean that affected individuals had no opportunity to protect themselves for an extended period after their information was first exposed. Delayed notification timelines like this one are a common source of frustration and legal scrutiny in data breach litigation, because the risk of misuse of stolen personal information does not wait for a company’s internal investigation to conclude. Individuals whose information was included in the compromised files should assume that the exposed data could be used for identity theft or fraud at any point, not only immediately after notification is sent.
MMR has stated that it implemented additional security measures following the incident to reduce the risk of similar events in the future, and it established a dedicated call center to answer questions from affected individuals. While these steps are a standard part of a company’s response to a confirmed breach, they do not undo the exposure that already occurred, and affected individuals should take independent steps to monitor their accounts and credit for signs of misuse.
Nationally, data breach notification laws generally require companies to notify affected individuals within a set window once the scope of a breach is known, but the requirement is typically tied to when a company has completed a reasonable investigation, not to the original date of intrusion. This structure means that individuals can remain unaware their information was exposed for months while a company’s internal or third-party forensic review runs its course, even though the underlying data theft may have occurred much earlier. Identity theft resulting from a stolen Social Security number or government identification number frequently does not surface immediately either; fraudulent accounts and tax filings can appear years after the original theft, which is why credit monitoring and identity protection services are typically offered for a limited enrollment window rather than indefinitely.
Because MMR’s records may include litigation, insurance, and healthcare-related documents belonging to former clients across a range of legal matters, the exposure is not necessarily limited to a single type of case or transaction. A breach touching a law firm’s broader case files can affect people who had no direct, recent interaction with the firm, simply because their records remained on file from a past matter. This is a common and often overlooked risk of any professional services provider that retains client records long after a matter has closed.
When Did This Breach Occur?
MMR reports that it first detected unusual activity on its network on December 8, 2025. The firm says it confirmed the scope of the incident and gathered sufficient information to notify affected individuals on August 18, 2026, and it began mailing written notice to potentially impacted individuals on September 10, 2026.
What Information Was Breached?
The personal information involved varied by individual but may have included names, Social Security numbers, driver’s license or state identification numbers, passport numbers, military identification numbers, other government-issued identification numbers, financial account information, health insurance information, and medical information. Not every affected individual necessarily had all of these data types exposed; MMR has said the specific information involved differed from person to person.
What You Can Do
If you received a notice from Midkiff, Muncie & Ross, P.C., consider taking the following steps to protect yourself:
- Enroll in the complimentary identity protection services through IDX that MMR is offering to eligible individuals before the December 10, 2026 deadline.
- Place a fraud alert or security freeze on your credit files with Equifax, Experian, and TransUnion.
- Regularly review your bank and credit card statements, credit reports, and health insurance explanation-of-benefits statements for unfamiliar activity.
- Be cautious of unsolicited calls, emails, or letters referencing this incident, as scammers sometimes use news of a breach to attempt further fraud.
- Contact MMR’s toll-free call center at 1-866-200-0898 if you have questions about whether your information was involved.
File a Data Breach Lawsuit Against Midkiff, Muncie & Ross, P.C.
If your personal information was compromised in the Midkiff, Muncie & Ross, P.C. data breach, you may be entitled to compensation. Companies and law firms that collect and store sensitive personal information have a duty to implement reasonable safeguards to protect it, and a failure to do so can leave victims exposed to identity theft, fraud, and significant time and expense trying to secure their accounts and identities.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.