Were you recently affected by a data breach?

Molod Spitz & DeSantis, P.C. Data Breach

New York law firm Molod Spitz & DeSantis, P.C. notified individuals in July 2026 of a security incident affecting its network that may have exposed personal information contained in firm files, some of which may have been accessed as far back as August 2025.

Molod Spitz & DeSantis, P.C.
Date of Breach: Incident discovered June 26, 2026 (files potentially accessed around August 15, 2025)
CAU logo

Who was affected:

Clients of Molod Spitz & DeSantis, P.C.

Impacted Data:

Full name and additional personal information (specific data types not publicly disclosed)

Molod Spitz & DeSantis, P.C., a New York law firm, recently notified individuals that a security incident affecting its network may have exposed personal information contained in the firm’s files. While the firm has not disclosed the specific cause of the incident, it has acknowledged that files containing personal information may have been accessed by an unauthorized party. Law firms and other professional service providers that store sensitive client and case-related information have a responsibility to protect it, and to promptly notify individuals when that information may have been compromised.

Molod Spitz & DeSantis, P.C.’s Data Breach Investigation

Molod Spitz & DeSantis, P.C. (“MSD”), a law firm based at 1430 Broadway in New York City, disclosed in a notification letter that it experienced a security incident impacting its computer network. According to the letter, MSD launched an investigation upon learning of the issue and worked with outside cybersecurity professionals to determine the scope of the incident. Following a forensic investigation and a manual document review, the firm determined on June 26, 2026 that files in the impacted systems, which may have been accessed or acquired by an unauthorized actor on or around August 15, 2025, contained personal information belonging to the individuals it notified.

MSD’s letter states that the affected files contained the recipient’s full name along with additional personal information, though the firm did not specify further categories of data in the portion of the letter made available. The firm said it has no evidence that any personal information has been or will be misused for identity theft or financial fraud as a direct result of the incident, but it is nonetheless offering complimentary credit monitoring services through Epiq – Privacy Solutions ID to affected individuals as a precaution.

Law firms have increasingly become a target for cybercriminals because of the sheer volume and sensitivity of personal, financial, and litigation-related information they maintain on behalf of clients and other parties, often for years after a matter has closed. Unlike hospitals or financial institutions, many law firms operate with comparatively modest dedicated cybersecurity staff and budgets relative to the sensitivity of the records they hold, a mismatch that has made the legal sector an attractive target for ransomware groups and data thieves in recent years. When a firm’s network is compromised, the exposed information can include not just current client records but historical case files containing Social Security numbers, financial account details, and other information tied to matters that may have concluded long ago.

The roughly ten-month gap between the reported date of unauthorized access (August 2025) and the firm’s confirmation of which individuals were affected (June 2026) is not unusual for incidents of this type. Forensic investigations into network intrusions frequently require firms to work with outside cybersecurity specialists to reconstruct what data may have been accessed, cross-reference affected files against current client and personnel records, and confirm mailing addresses before notification letters can be sent, a process that can take many months even when an organization moves diligently. Massachusetts and other states impose notification obligations once an organization determines personal information was compromised, but the process of reaching that determination is often the most time-consuming part of the response.

Individuals who receive a notification letter of this kind, particularly one where the exact categories of exposed information were not spelled out, should treat the incident conservatively and assume that more sensitive information they provided to the firm, potentially including Social Security numbers or financial account information tied to a legal matter, could have been involved. Recipients should also be alert to phishing attempts that specifically reference the breach or purport to be from MSD, its credit monitoring provider, or a credit bureau, since scammers frequently exploit publicized data breaches to trick victims into providing additional sensitive information under the guise of “verifying” their identity or enrolling in protection services.

When Did This Breach Occur?

According to MSD’s notification letter, files that may have been accessed by an unauthorized actor were potentially exposed on or around August 15, 2025. MSD states that it discovered, through a forensic investigation and manual document review, on June 26, 2026 that files in the impacted systems contained the recipient’s personal information. The firm’s notification letters to affected individuals were issued in July 2026.

What Information Was Breached?

MSD’s letter confirms that the at-risk files contained each affected individual’s full name, along with additional personal information that was not fully specified in the portion of the letter made publicly available. Because the complete list of exposed data categories has not been disclosed, affected individuals should consider that other personal information they provided to the firm in connection with a legal matter could have been included among the exposed files.

What You Can Do

MSD is offering affected individuals complimentary credit monitoring services through Epiq – Privacy Solutions ID. Recommended steps for anyone who received a notification letter include:

  • Enroll in the complimentary credit monitoring services described in the notification letter before the enrollment deadline
  • Place an initial or extended fraud alert on your credit files with Equifax, Experian, or TransUnion
  • Consider placing a security freeze on your credit reports
  • Request a free copy of your credit report at annualcreditreport.com
  • Regularly review financial account statements and credit reports for suspicious activity

File a Data Breach Lawsuit Against Molod Spitz & DeSantis, P.C.

If you received a data breach notification letter from Molod Spitz & DeSantis, P.C., you may be entitled to compensation. Organizations that collect and store sensitive personal information have a legal obligation to protect it, and when that obligation is not met, affected individuals may have legal options.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 8, 2025 to August 27, 2025 (discovered July 16, 2026)
Date of Breach: September 5, 2025 (discovered July 6, 2026)
Date of Breach: On or about April 7, 2026 (ransomware detected)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.