Mogren, Glessner & Ahrens, P.S., a Renton, Washington law firm, has notified 1,379 current and former clients that their personal and financial information was compromised after hackers accessed the firm’s main server and later claimed to have stolen a substantial volume of client data. Law firms hold uniquely sensitive records for the people they represent, and they have a responsibility to protect that information from unauthorized access.
Mogren, Glessner & Ahrens, P.S.’s Data Breach Investigation
According to a letter the firm sent to the Washington State Attorney General’s Office, a breach of the firm’s main server occurred on June 9, 2026, and was discovered the following day, June 10, 2026. The firm’s IT specialist worked to secure the server and initially believed the intruders had encrypted files but had not been able to remove any data. Based on that assessment, the firm restored the server from a backup, changed all passwords, and resumed operations, instituting a new policy of disconnecting the server from the internet outside of business hours.
That initial assessment changed on August 20, 2026, when the firm received an email from a hacker demanding payment and threatening to release the firm’s data. The email included attachments of pleadings created by the firm along with other files that appeared to originate from an employee’s workstation, and the hacker claimed to possess 380 gigabytes of the firm’s data. Upon realizing that data had, in fact, been taken, the firm began notifying clients and sent written notice by U.S. mail to 1,379 individuals on August 31, 2026.
Ransomware and extortion-style attacks against law firms have become increasingly common in recent years, in part because firms retain years of highly sensitive client records, including financial account information, tax filings, and property records, in a single, centralized system. Attackers who compromise a law firm’s server or email accounts often wait to determine the value of what they have obtained before revealing themselves, which is part of why the firm’s initial belief that no data had been stolen changed only after the hackers made direct contact more than two months after the intrusion was first discovered.
Small and mid-size professional service firms, including law offices, are frequently targeted by ransomware groups precisely because they tend to hold large volumes of sensitive client data while often running smaller IT operations than large corporations or financial institutions. This mismatch between the sensitivity of the data held and the resources available to defend it is a pattern security researchers have documented across the legal industry for years, and it helps explain why a single compromised workstation or server can lead to an extortion attempt affecting well over a thousand people at once.
The delay between an initial breach and a firm’s recognition that data was actually exfiltrated, as happened here between June and August 2026, is also a recurring feature of ransomware-style intrusions. Attackers frequently gain access to a network well before deploying encryption or making contact, using that time to quietly copy files before revealing themselves through an extortion demand. This means the window during which sensitive data was exposed can be considerably longer than the period during which any visible disruption to the target’s systems occurred, which is one reason regulators encourage forensic investigations to examine the full scope of network access rather than relying solely on the date suspicious activity was first noticed.
The firm stated that it regularly handles client records containing names, dates of birth, Social Security numbers, passwords, financial account numbers, physical addresses, email addresses, statutory warranty deeds, and tax returns, and that the notification was sent to all clients for whom the firm has held confidential information over the last sixteen years. Because the firm could not determine with certainty how much of its four terabytes of stored data the hackers actually accessed or downloaded, the notification was sent broadly to affected clients out of an abundance of caution.
When Social Security numbers, financial account numbers, and tax return information are potentially exposed together, affected individuals face an elevated risk of both financial account fraud and tax-related identity theft, in which a fraudster files a return in a victim’s name to claim a refund. Because law firm client files can also contain deeply personal case details, individuals whose information was involved in a breach like this one should remain alert to targeted phishing attempts that reference specific, accurate details about their own legal matters.
When Did This Breach Occur?
The breach of the firm’s server occurred on or about June 9, 2026, and was discovered on June 10, 2026. The firm learned that data had actually been taken on August 20, 2026, after receiving a message from the hackers, and sent written notice to affected clients on August 31, 2026.
What Information Was Breached?
Mogren, Glessner & Ahrens reported that the information potentially involved includes names, dates of birth, Social Security numbers, passwords, financial account numbers, physical addresses, email addresses, statutory warranty deeds, and tax returns, drawn from client files maintained by the firm over the last sixteen years.
What You Can Do
If you received a notice from Mogren, Glessner & Ahrens, P.S., consider taking the following steps:
- Review your financial account statements and credit reports regularly for unfamiliar activity.
- Place a fraud alert or security freeze on your credit files with Equifax, Experian, and TransUnion.
- Change passwords for any accounts you may have shared with the firm or discussed in email correspondence.
- File your tax return as early as possible and watch for any notices of a duplicate filing under your Social Security number.
- Report any suspected identity theft or fraud to the Federal Trade Commission and your state attorney general.
File a Data Breach Lawsuit Against Mogren, Glessner & Ahrens, P.S.
If you received a notice that your personal or financial information was exposed in the Mogren, Glessner & Ahrens data breach, you may be entitled to compensation. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.