Taft Stettinius & Hollister is a large, multi-state law firm that handles sensitive personal information for many clients across the country. Vermont’s Attorney General was recently notified that a data breach exposed personal information belonging to a number of the firm’s clients.
Law firms and other organizations that collect and store Social Security numbers and other personal data have a responsibility to protect that information from unauthorized access, and to promptly notify anyone affected when a breach occurs.
Taft Stettinius & Hollister’s Data Breach Investigation
On July 29, 2026, Taft Stettinius & Hollister LLP reported a data breach to the Vermont Attorney General’s Office, disclosing that Social Security numbers belonging to Vermont residents were compromised. According to the filing, 16 Vermont residents were affected by the incident, which was classified under the Other Commercial reporting category by the Vermont AGO. Vermont’s breach-notification program no longer publishes copies of the underlying consumer notification letters for reasons related to digital accessibility, so the specifics of how the breach occurred, when it was first detected, and what steps Taft has taken in response have not been made publicly available through the state’s own disclosure. Taft Stettinius & Hollister, commonly known simply as Taft, is an AmLaw 100 law firm founded in 1885 and headquartered in Cincinnati, Ohio, with more than twenty offices across the United States. As a large, multi-state legal practice, the firm holds sensitive personal and financial information for a substantial number of clients, employees, and other individuals in the ordinary course of its business.
This is not the first time Taft has disclosed a security incident. In late 2023, the firm reported that it had been the target of a ransomware attack that resulted in unauthorized access to certain internal systems, and it separately notified residents of a number of other states, including Maryland, Massachusetts, and Maine, about that earlier event. That 2023 ransomware incident and the newly reported 2026 Vermont filing are separate matters, reported to different state regulators at different times, and involve different confirmed facts; residents should not assume the two incidents share the same cause, scope, or affected population.
Law firms have increasingly become attractive targets for cybercriminals because of the sheer volume and sensitivity of the information they hold on behalf of clients, including financial records, litigation files, medical histories, and government identification numbers that frequently pass through a firm’s systems during the course of representation. Because a law firm often serves as a central repository connecting many different clients’ most sensitive records, a single successful intrusion can expose personal information belonging to individuals who may have had no direct relationship with the attacker or even any reason to expect their data was held by the firm in the first place.
When Social Security numbers are exposed in a data breach, the risk to affected individuals extends well beyond the immediate incident. A Social Security number is one of the most valuable pieces of information to identity thieves because it can be used to open new lines of credit, file fraudulent tax returns, apply for loans, or create entirely new identities in a victim’s name. Unlike a compromised password or credit card number, a Social Security number generally cannot be changed, which means the exposure can create risk that persists for years after the breach itself has been resolved.
State data breach notification laws, including Vermont’s own reporting requirements, are designed to ensure that individuals learn promptly when their personal information has been compromised so they can take protective action. Reporting timelines and required disclosures vary somewhat from state to state, but the underlying purpose is the same: giving affected individuals the earliest possible opportunity to monitor their accounts, place fraud alerts, or freeze their credit before stolen information can be misused.
Individuals who receive a breach notification letter should also be alert to a secondary risk: scammers frequently use news of a real breach as cover for follow-up phishing attempts, sending fake notification emails or text messages that impersonate the breached company in an effort to trick recipients into providing even more personal information. Anyone who receives a notice about this incident should verify its authenticity independently rather than clicking links or calling phone numbers provided in an unsolicited message, and should be especially cautious of any communication asking them to verify or update personal details or account credentials in response to the breach.
When Did This Breach Occur?
Taft Stettinius & Hollister reported this breach to the Vermont Attorney General’s Office on July 29, 2026. The Vermont AGO’s public disclosure table lists the date the report was received but does not include the date the underlying unauthorized access actually occurred, when it was first detected internally by the firm, or when notification letters were sent to affected individuals. Vermont discontinued posting the underlying consumer notification letters that would typically supply that detail, citing digital accessibility requirements for government websites, so those specific dates are not currently available from any public source. This 2026 Vermont filing is a distinct filing from Taft’s earlier, separately reported ransomware incident from late 2023, which followed its own separate timeline and notification process in other states. As more information becomes available, this page will be updated to reflect the confirmed breach and detection dates.
What Information Was Breached?
According to Taft’s filing with the Vermont Attorney General, the personal information involved in this breach included Social Security numbers belonging to affected Vermont residents. The filing does not specify whether other categories of personal information, such as names, addresses, financial account numbers, or health information, were also involved, and Vermont’s disclosure table lists only the broad category of data reported for this incident. Because a Social Security number is highly sensitive on its own, even a breach limited to that single data element can create a serious risk of identity theft and fraud for the 16 individuals identified in the filing. Anyone who received or later receives a formal notification letter from Taft Stettinius & Hollister should review it carefully, as it may identify additional data categories specific to their own individual record that are not reflected in the state’s summary.
What You Can Do
If you were notified that your information was involved in this breach, there are several steps you can take to help protect yourself:
- Carefully review any notification letter you receive from Taft Stettinius & Hollister for specific instructions and any complimentary credit monitoring or identity protection services offered.
- Place a fraud alert or credit freeze with the three major credit bureaus, Equifax, Experian, and TransUnion, to make it harder for anyone to open new accounts in your name.
- Monitor your bank and credit card statements, as well as your credit reports, for any unfamiliar activity.
- Be cautious of unsolicited phone calls, emails, or text messages referencing this breach, and never provide personal information in response to a message you did not initiate.
- Consider filing your taxes early, since a stolen Social Security number can be used to file a fraudulent tax return in your name.
File a Data Breach Lawsuit Against Taft Stettinius & Hollister
If you were affected by this breach, you may have legal options available to you. Individuals whose Social Security numbers or other personal information is exposed due to a company’s failure to reasonably secure it may be entitled to pursue compensation through a data breach lawsuit.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.