Were you recently affected by a data breach?

Squire Patton Boggs Data Breach

Squire Patton Boggs (US) LLP reported a data breach to the Vermont Attorney General on October 8, 2026. The listing says 2 Vermont residents were notified and that Social Security numbers were among the information involved.

Squire Patton Boggs
Date of Breach: Not publicly disclosed (reported October 8, 2026)
CAU logo

Who was affected:

Clients of Squire Patton Boggs

Impacted Data:

Social Security numbers

Squire Patton Boggs (US) LLP has filed a data breach notice with the Vermont Attorney General’s Office, listed on October 8, 2026. The listing states that Social Security numbers were involved and that 2 Vermont residents were affected.

If you received a letter from the firm, or believe your information was in files the firm held, here is what has been made public so far and what you can do about it.

Squire Patton Boggs’s Data Breach Investigation

Squire Patton Boggs (US) LLP is the United States arm of a large international law firm. Law firms hold an unusual mix of personal records. Besides information about their own employees and job applicants, they store files for clients, opposing parties, witnesses, and people named in transactions or disputes. That is why a security incident at a firm can touch people who have never had any direct relationship with it.

The incident described on this page became public through the Vermont Attorney General’s security breach notice listing. Vermont requires organizations to tell the Attorney General’s Office when a breach involves the personal information of Vermont residents, and the office posts a summary table of the filings it receives. The entry for this firm shows a date reported of October 8, 2026, classifies the reporting organization as Other Commercial, lists 2 Vermont residents as affected, and names Social Security numbers as the category of data breached.

That is the full extent of what the listing provides. Vermont no longer posts the underlying notice letters on its website, and we did not find a notice on the firm’s own site, a press statement, or a filing from another state regulator that expands on the listing. For that reason, this page does not state how the incident happened, when it began, how long it lasted, or how many people were affected nationwide. Those details have not been made public in the sources we reviewed, and we are not going to guess at them.

The number in the listing needs careful reading. It counts only Vermont residents. Organizations that notify people in many states typically file a separate notice with each state regulator that requires one, and each filing reports only that state’s residents. A figure of 2 for Vermont therefore says very little about the total. It could be a small piece of a much larger notification effort, or it could reflect a very limited incident. Without a filing from a state that publishes a total, there is no way to tell which.

Social Security numbers are among the most sensitive identifiers a person has. Unlike a password or a payment card number, a Social Security number cannot be easily changed, and it stays useful to criminals for years. Combined with a name and date of birth, it can be used to open new credit accounts, file false tax returns, apply for benefits, or pass identity checks with banks and employers. The listing does not say whether other information, such as names, addresses or financial details, was involved alongside the Social Security numbers, although a notice sent to a person would necessarily identify them by name.

Professional services firms are a recurring target for cyberattacks and for accidental exposures. They hold concentrated, high-value records, they exchange large files with clients by email and shared portals, and they rely on outside vendors for document management, e-discovery and other technology. A problem at any of those points can lead to a notification. We are describing the general landscape only. The Vermont listing does not say whether the firm’s own systems or a third-party provider’s systems were involved, and nothing here should be read as a finding about the cause of this incident.

If you received a notice from Squire Patton Boggs (US) LLP, read it closely. The letter is the best source for what applies to you, including which data elements relate to your own file and whether the firm is offering credit monitoring or identity protection at no cost. If you expect that the firm may have held your records, for instance because you were an employee, a job applicant, or a party in a matter the firm handled, but you have not received anything, you can contact the firm to ask whether your information was involved.

People who learn that their Social Security number was exposed often wonder how worried to be. A sensible approach is to act on the protective steps listed further down this page, which cost little and take only a short time, rather than to wait for evidence of misuse. A credit freeze in particular is free, can be placed and lifted online, and stops most new accounts from being opened in your name.

A data breach class action is one way people affected by a security incident can seek accountability from an organization that did not adequately protect their information. Whether a claim makes sense depends on facts that are still emerging in this matter, which is why speaking with a lawyer about your own situation is a reasonable step if you were notified.

When Did This Breach Occur?

The Vermont Attorney General’s listing shows that the firm reported the breach on October 8, 2026. That is the only date the listing provides.

The date the incident began, the date it was discovered, and the date notice letters were mailed have not been made public in the sources we reviewed. The date reported to a regulator is not the same as the date of the breach, and an incident can predate the filing by weeks or months.

What Information Was Breached?

The Vermont listing identifies Social Security numbers as the category of data breached. It does not list any other categories.

The listing does not say whether the Social Security numbers appeared together with names, addresses or other details, and it does not describe which groups of people were affected. Your own notice letter is the best source for what applies to you.

What You Can Do

If you received a notice from Squire Patton Boggs (US) LLP or believe you may be affected, consider these steps:

  • Read the notice carefully and keep it, along with any enrollment details for protection services it offers.
  • Place a free fraud alert or a credit freeze with Equifax, Experian and TransUnion, and get your reports free at annualcreditreport.com.
  • Watch your financial accounts, tax records and any insurance or medical statements for activity you do not recognize.
  • Be skeptical of unexpected calls, texts or emails that mention the organization, and report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.

File a Data Breach Lawsuit Against Squire Patton Boggs

If your personal information may have been exposed in this incident, you may have legal options. Organizations that hold sensitive personal information are expected to safeguard it, and a class action can help hold an organization accountable when it fails to do so.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reportedly October 6, 2026 (unconfirmed)
Date of Breach: Discovered August 10, 2026
Date of Breach: Not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.