WILMER CUTLER PICKERING HALE AND DORR LLP
bd_88b9137fcfba81da · schema v1 · pii pii-v1
Full breach record for WILMER CUTLER PICKERING HALE AND DORR LLP →Wilmer Cutler Pickering Hale and Dorr LLP disclosed a data security incident on July 10, 2026, affecting clients in multiple jurisdictions including Massachusetts. On May 8, 2026, an employee mistakenly provided client names and Social Security Numbers to an unauthorized third party who misrepresented their identity. The firm investigated, engaged forensic experts, and notified federal law enforcement. The incident was isolated, systems were not directly accessed, and no further misuse was detected. Affected individuals were offered 24 months of credit monitoring via Experian.
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_39ac1dd623acd6eeMassachusetts State AGfiled 2026-07-01Verified
- bd_0f58950e180387e0California State AGfiled 2026-07-10(9d gap)Verified
- bd_9b30d53ab5f53287Vermont State AGfiled 2026-07-10(9d gap)Verified
- bd_a307582915e1b0dcNew Hampshire State AGfiled 2026-07-10(9d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 13d gap
- bd_87849f3a47c4a66eTexas State AGfiled 2026-07-14(13d gap)Candidate
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1117-wilmer-cutler-pickering-hale-and-dorr-llp/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2026
- Raw hash
- e459eb5b9edd77faa927f49c37fbf50f55be4714c84cba993bb3fd1112e57f3a
Reporting entity
- Name
- WILMER CUTLER PICKERING HALE AND DORR LLPnorm: wilmer cutler pickering hale and dorr
Victim entity
- Name
- WILMER CUTLER PICKERING HALE AND DORR LLPnorm: wilmer cutler pickering hale and dorr
Incident
- Discovered
- May 8, 2026
- Materiality determined
- —
- Notification sent
- Jul 10, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified federal law enforcement authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- MA AG >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.