Were you recently affected by a data breach?

Mogren, Glessner & Ahrens, P.S. Data Breach

Mogren, Glessner & Ahrens, P.S., a Renton, Washington law firm, notified 1,379 clients that its server was breached in June 2026 and data was later confirmed stolen by hackers demanding payment.

Mogren, Glessner & Ahrens, P.S.
Date of Breach: June 9, 2026
CAU logo

Who was affected:

Clients of Mogren, Glessner & Ahrens, P.S.

Impacted Data:

Names, dates of birth, Social Security numbers, passwords, financial account numbers, physical addresses, email addresses, statutory warranty deeds, and tax returns

Mogren, Glessner & Ahrens, P.S., a Renton, Washington law firm, has notified 1,379 current and former clients that their personal and financial information was compromised after hackers accessed the firm’s main server and later claimed to have stolen a substantial volume of client data. Law firms hold uniquely sensitive records for the people they represent, and they have a responsibility to protect that information from unauthorized access.

Mogren, Glessner & Ahrens, P.S.’s Data Breach Investigation

According to a letter the firm sent to the Washington State Attorney General’s Office, a breach of the firm’s main server occurred on June 9, 2026, and was discovered the following day, June 10, 2026. The firm’s IT specialist worked to secure the server and initially believed the intruders had encrypted files but had not been able to remove any data. Based on that assessment, the firm restored the server from a backup, changed all passwords, and resumed operations, instituting a new policy of disconnecting the server from the internet outside of business hours.

That initial assessment changed on August 20, 2026, when the firm received an email from a hacker demanding payment and threatening to release the firm’s data. The email included attachments of pleadings created by the firm along with other files that appeared to originate from an employee’s workstation, and the hacker claimed to possess 380 gigabytes of the firm’s data. Upon realizing that data had, in fact, been taken, the firm began notifying clients and sent written notice by U.S. mail to 1,379 individuals on August 31, 2026.

Ransomware and extortion-style attacks against law firms have become increasingly common in recent years, in part because firms retain years of highly sensitive client records, including financial account information, tax filings, and property records, in a single, centralized system. Attackers who compromise a law firm’s server or email accounts often wait to determine the value of what they have obtained before revealing themselves, which is part of why the firm’s initial belief that no data had been stolen changed only after the hackers made direct contact more than two months after the intrusion was first discovered.

Small and mid-size professional service firms, including law offices, are frequently targeted by ransomware groups precisely because they tend to hold large volumes of sensitive client data while often running smaller IT operations than large corporations or financial institutions. This mismatch between the sensitivity of the data held and the resources available to defend it is a pattern security researchers have documented across the legal industry for years, and it helps explain why a single compromised workstation or server can lead to an extortion attempt affecting well over a thousand people at once.

The delay between an initial breach and a firm’s recognition that data was actually exfiltrated, as happened here between June and August 2026, is also a recurring feature of ransomware-style intrusions. Attackers frequently gain access to a network well before deploying encryption or making contact, using that time to quietly copy files before revealing themselves through an extortion demand. This means the window during which sensitive data was exposed can be considerably longer than the period during which any visible disruption to the target’s systems occurred, which is one reason regulators encourage forensic investigations to examine the full scope of network access rather than relying solely on the date suspicious activity was first noticed.

The firm stated that it regularly handles client records containing names, dates of birth, Social Security numbers, passwords, financial account numbers, physical addresses, email addresses, statutory warranty deeds, and tax returns, and that the notification was sent to all clients for whom the firm has held confidential information over the last sixteen years. Because the firm could not determine with certainty how much of its four terabytes of stored data the hackers actually accessed or downloaded, the notification was sent broadly to affected clients out of an abundance of caution.

When Social Security numbers, financial account numbers, and tax return information are potentially exposed together, affected individuals face an elevated risk of both financial account fraud and tax-related identity theft, in which a fraudster files a return in a victim’s name to claim a refund. Because law firm client files can also contain deeply personal case details, individuals whose information was involved in a breach like this one should remain alert to targeted phishing attempts that reference specific, accurate details about their own legal matters.

When Did This Breach Occur?

The breach of the firm’s server occurred on or about June 9, 2026, and was discovered on June 10, 2026. The firm learned that data had actually been taken on August 20, 2026, after receiving a message from the hackers, and sent written notice to affected clients on August 31, 2026.

What Information Was Breached?

Mogren, Glessner & Ahrens reported that the information potentially involved includes names, dates of birth, Social Security numbers, passwords, financial account numbers, physical addresses, email addresses, statutory warranty deeds, and tax returns, drawn from client files maintained by the firm over the last sixteen years.

What You Can Do

If you received a notice from Mogren, Glessner & Ahrens, P.S., consider taking the following steps:

  • Review your financial account statements and credit reports regularly for unfamiliar activity.
  • Place a fraud alert or security freeze on your credit files with Equifax, Experian, and TransUnion.
  • Change passwords for any accounts you may have shared with the firm or discussed in email correspondence.
  • File your tax return as early as possible and watch for any notices of a duplicate filing under your Social Security number.
  • Report any suspected identity theft or fraud to the Federal Trade Commission and your state attorney general.

File a Data Breach Lawsuit Against Mogren, Glessner & Ahrens, P.S.

If you received a notice that your personal or financial information was exposed in the Mogren, Glessner & Ahrens data breach, you may be entitled to compensation. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to the Texas Attorney General on September 17, 2026 (specific incident dates not yet publicly disclosed)
Date of Breach: Reported to the Texas Attorney General on September 17, 2026 (specific incident dates not yet publicly disclosed)
Date of Breach: July 30, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.