Molod Spitz & DeSantis, P.C., a New York law firm, recently notified individuals that a security incident affecting its network may have exposed personal information contained in the firm’s files. While the firm has not disclosed the specific cause of the incident, it has acknowledged that files containing personal information may have been accessed by an unauthorized party. Law firms and other professional service providers that store sensitive client and case-related information have a responsibility to protect it, and to promptly notify individuals when that information may have been compromised.
Molod Spitz & DeSantis, P.C.’s Data Breach Investigation
Molod Spitz & DeSantis, P.C. (“MSD”), a law firm based at 1430 Broadway in New York City, disclosed in a notification letter that it experienced a security incident impacting its computer network. According to the letter, MSD launched an investigation upon learning of the issue and worked with outside cybersecurity professionals to determine the scope of the incident. Following a forensic investigation and a manual document review, the firm determined on June 26, 2026 that files in the impacted systems, which may have been accessed or acquired by an unauthorized actor on or around August 15, 2025, contained personal information belonging to the individuals it notified.
MSD’s letter states that the affected files contained the recipient’s full name along with additional personal information, though the firm did not specify further categories of data in the portion of the letter made available. The firm said it has no evidence that any personal information has been or will be misused for identity theft or financial fraud as a direct result of the incident, but it is nonetheless offering complimentary credit monitoring services through Epiq – Privacy Solutions ID to affected individuals as a precaution.
Law firms have increasingly become a target for cybercriminals because of the sheer volume and sensitivity of personal, financial, and litigation-related information they maintain on behalf of clients and other parties, often for years after a matter has closed. Unlike hospitals or financial institutions, many law firms operate with comparatively modest dedicated cybersecurity staff and budgets relative to the sensitivity of the records they hold, a mismatch that has made the legal sector an attractive target for ransomware groups and data thieves in recent years. When a firm’s network is compromised, the exposed information can include not just current client records but historical case files containing Social Security numbers, financial account details, and other information tied to matters that may have concluded long ago.
The roughly ten-month gap between the reported date of unauthorized access (August 2025) and the firm’s confirmation of which individuals were affected (June 2026) is not unusual for incidents of this type. Forensic investigations into network intrusions frequently require firms to work with outside cybersecurity specialists to reconstruct what data may have been accessed, cross-reference affected files against current client and personnel records, and confirm mailing addresses before notification letters can be sent, a process that can take many months even when an organization moves diligently. Massachusetts and other states impose notification obligations once an organization determines personal information was compromised, but the process of reaching that determination is often the most time-consuming part of the response.
Individuals who receive a notification letter of this kind, particularly one where the exact categories of exposed information were not spelled out, should treat the incident conservatively and assume that more sensitive information they provided to the firm, potentially including Social Security numbers or financial account information tied to a legal matter, could have been involved. Recipients should also be alert to phishing attempts that specifically reference the breach or purport to be from MSD, its credit monitoring provider, or a credit bureau, since scammers frequently exploit publicized data breaches to trick victims into providing additional sensitive information under the guise of “verifying” their identity or enrolling in protection services.
When Did This Breach Occur?
According to MSD’s notification letter, files that may have been accessed by an unauthorized actor were potentially exposed on or around August 15, 2025. MSD states that it discovered, through a forensic investigation and manual document review, on June 26, 2026 that files in the impacted systems contained the recipient’s personal information. The firm’s notification letters to affected individuals were issued in July 2026.
What Information Was Breached?
MSD’s letter confirms that the at-risk files contained each affected individual’s full name, along with additional personal information that was not fully specified in the portion of the letter made publicly available. Because the complete list of exposed data categories has not been disclosed, affected individuals should consider that other personal information they provided to the firm in connection with a legal matter could have been included among the exposed files.
What You Can Do
MSD is offering affected individuals complimentary credit monitoring services through Epiq – Privacy Solutions ID. Recommended steps for anyone who received a notification letter include:
- Enroll in the complimentary credit monitoring services described in the notification letter before the enrollment deadline
- Place an initial or extended fraud alert on your credit files with Equifax, Experian, or TransUnion
- Consider placing a security freeze on your credit reports
- Request a free copy of your credit report at annualcreditreport.com
- Regularly review financial account statements and credit reports for suspicious activity
File a Data Breach Lawsuit Against Molod Spitz & DeSantis, P.C.
If you received a data breach notification letter from Molod Spitz & DeSantis, P.C., you may be entitled to compensation. Organizations that collect and store sensitive personal information have a legal obligation to protect it, and when that obligation is not met, affected individuals may have legal options.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.