GORLICK, KRAVITZ & LISTHAUS P.C.
bd_83585351ef572045 · schema v1 · pii pii-v1
Full breach record for GORLICK, KRAVITZ & LISTHAUS P.C. →Gorlick, Kravitz, & Listhaus, P.C. (GKL) notified Massachusetts residents of a cybersecurity incident where an unauthorized actor gained access to its network environment. An extensive forensic investigation and manual document review concluded on December 3, 2025, confirming that some personal and protected health information (PHI) was accessed. GKL engaged external cybersecurity professionals, remediated the issue, and is offering complimentary identity theft protection services. No indication of misuse was found.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Jan 2, 2026
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteakirabd_83884595b9f3490d2026-01-15 · +13dVerified
Regulatory filings (1) · sorted by filing gap
- New Hampshire State AGbd_b409c6e8465ab68a2026-01-05 · +3dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.