GRAYROBINSON, P.A.
ent_019dd18535683065e89d5bcc8cb7a513
Disclosures
16
State AG · HHS OCR · 12 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
80,383
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- GRAYROBINSON, P.A.
- Normalized
- grayrobinson— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300PNSKLYYJMLTR95
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (16)newest first
- South Carolina State AGas victim2026-05-07
GrayRobinson, P.A. notified South Carolina residents of a cybersecurity incident where unauthorized access occurred between March 5 and March 24, 2025. The firm detected the breach on March 24, 2025, and determined on April 13, 2026, that full names were potentially exposed. No financial fraud evidence was found. The firm engaged law enforcement and external cybersecurity professionals, and offered complimentary credit monitoring.
- New Hampshire State AGas victim2026-05-07
GrayRobinson, P.A., a law firm, notified the New Hampshire Attorney General that an unauthorized actor accessed its network between March 5 and March 24, 2025. GrayRobinson discovered the breach on April 13, 2026, after a forensic investigation. The incident potentially exposed personal information, including names, DOBs, SSNs, driver's license numbers, financial account info, and medical data, for 41 New Hampshire residents. GrayRobinson reported the incident to law enforcement, engaged external cybersecurity professionals, and is offering one year of complimentary credit monitoring to affected residents.
- Vermont State AGas victim2026-05-05
GreyRobinson, P.A. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-05-05. The reporting organization type is Other Commercial. 26 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit or Debit Account Info, Health Records.
- Texas State AGas victim2026-05-05
GrayRobinson, P.A. based in Orlando, Florida, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-04-13 and reported on 2026-05-05. 578 Texas residents were affected. 80,383 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via U.S. Mail.
- Maine State AGas victim2026-05-04
GrayRobinson, P.A. reported an external system breach (hacking) occurring between March 5 and March 24, 2025. The incident was discovered on April 13, 2026. Approximately 80,383 individuals were affected, including 56 Maine residents. The breach potentially exposed names and personal identifiers. GrayRobinson secured its network, notified law enforcement, and engaged external cybersecurity professionals. Affected individuals were offered 12 months of Experian credit monitoring.
- California State AGas victim2026-05-04
GrayRobinson, P.A. detected unauthorized access to its network on March 24, 2025. Investigation determined files may have been accessed or removed between March 5 and March 24, 2025. Affected data includes full name and Social Security numbers. The firm secured the network, reported to law enforcement, engaged external cybersecurity professionals, and offered complimentary identity monitoring services.
- New Hampshire State AGas victim2026-04-29
GrayRobinson, P.A. notified the New Hampshire Attorney General of a cybersecurity incident affecting 34 NH residents. Unauthorized access occurred between March 5, 2025, and March 24, 2025. GrayRobinson discovered the breach on April 13, 2026, after a forensic investigation. Impacted data included names, DOB, medical info, financial account info, driver's license numbers, and SSNs. GrayRobinson secured the network, reported to law enforcement, and offered 12 months of credit monitoring. Notification letters were mailed on April 24, 2026.
- Massachusetts State AGas victim2026-04-24
GrayRobinson, P.A. detected unauthorized access to its network on March 24, 2025. Investigation determined files may have been accessed or removed between March 5 and March 24, 2025. Affected data included full names. The firm secured its network, reported to law enforcement, engaged external cybersecurity professionals, and offered complimentary credit monitoring via Experian IdentityWorks.
- Montana State AGas victim2026-04-24
GrayRobinson P.A. notified Montana residents of a cybersecurity incident where unauthorized access occurred between March 5 and March 24, 2025. The firm detected the access on March 24, 2025, and determined on April 13, 2026, that personal information (names) may have been exposed. GrayRobinson secured its network, reported to law enforcement, and engaged external cybersecurity professionals. Complimentary credit monitoring via Experian IdentityWorks is offered.
- Nebraska State AGas victim2026-04-24
GrayRobinson, P.A. notified Nebraska residents of a cybersecurity incident occurring between March 5 and March 24, 2025. Unauthorized access resulted in the potential exposure of personal information, including full names. GrayRobinson secured its network, reported the incident to law enforcement, and engaged external cybersecurity professionals. Affected individuals were offered complimentary credit monitoring via Experian IdentityWorks. The notification letter was dated April 13, 2026.
- FLORIDAHHS OCRas victim2026-04-24
GrayRobinson, P.A. reported to HHS on 2026-04-24 a Hacking/IT Incident affecting 54,131 individuals. Breached information located on Network Server. GrayRobinson, P.A. is identified as a Business Associate.
- California State AGas victim2026-04-24
GrayRobinson, P.A. detected unauthorized access to its network on March 24, 2025. The incident involved potential exposure of personal information, including full names and Social Security numbers, for individuals whose data may have been accessed between March 5, 2025, and March 24, 2025. The firm secured its network, reported the incident to law enforcement, and engaged external cybersecurity professionals. Affected individuals are being offered complimentary credit monitoring services.
- Maine State AGas victim2026-04-24
GrayRobinson P.A., a law firm, disclosed an external system breach (hacking) occurring between March 5 and March 24, 2025. The incident potentially exposed the names of approximately 65,113 individuals, including 52 Maine residents. GrayRobinson secured its network, notified law enforcement, and engaged external cybersecurity professionals. Notices were sent on April 24, 2026, offering 12 months of credit monitoring via Experian.
- Indiana State AGas victim2026-04-24
GrayRobinson P.A. reported a data breach to the Indiana Attorney General. The breach occurred on 2025-03-05 and was reported on 2026-04-24. 221 Indiana residents were affected. 65,113 individuals affected in total.
- Nebraska State AGas victim2026-04-24
GrayRobinson, P.A. reported a cybersecurity incident to the Nebraska Attorney General. Unauthorized access occurred between March 5, 2025, and March 24, 2025. The firm secured its network, notified law enforcement, and engaged external cybersecurity professionals. Personal information, including full names, was potentially exposed. The company offered complimentary credit monitoring via Experian IdentityWorks.
- Illinois State AGas victim2026-04-01
GRAYROBINSON P.A. filed a data-breach notice with the Illinois Attorney General in April 2026 (case 26-04-1157). The register records the breach as discovered on April 13, 2026. Personal information types reported: drivers license, financial account number, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.