SMITH GAMBRELL & RUSSELL LLP
ent_ca22cf2746749b228b26d7fd
Disclosures
13
State AG · HHS OCR · 9 jurisdictions
Incidents
6
filings grouped by incident
Max affected reported
220,000
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SMITH GAMBRELL & RUSSELL LLP
- Normalized
- smith gambrell russell— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300N24MY7YQHNQC78
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- sgrlaw.com
Disclosure history (13)newest first
- 🏛️Massachusetts State AGas reporting2026-07-01
T.A. Solberg Co., Inc. reported unauthorized network access on March 3, 2026, affecting 6 Massachusetts residents. The incident involved the viewing of personal and protected health information. The company engaged a cybersecurity firm, took systems offline, and provided 24 months of identity monitoring to affected individuals. Notification was filed with the Massachusetts AG on July 3, 2026.
- ⛰️New Hampshire State AGas reporting2026-06-23
AssuranceAmerica Managing General Agency, LLC notified the New Hampshire Attorney General of a data security incident affecting 462 NH residents. The breach involved unauthorized access to IT systems following a targeted phishing attack on an employee on March 16, 2026. Data copied included names, contact info, insurance policy details, and driver's license numbers. The company engaged forensic specialists, notified law enforcement, reset credentials, and implemented enhanced security controls including XDR monitoring and MFA.
- ⛰️New Hampshire State AGas reporting2026-06-19
Kentucky Mountain Health Alliance, Inc. (KMHA) notified the New Hampshire Attorney General of a data event affecting one NH resident. Unauthorized access occurred on or around September 16, 2025, involving the viewing and obtaining of files containing SSNs, driver's licenses, passport numbers, financial account info, and PHI. KMHA took systems offline, engaged a cybersecurity firm, and reported to law enforcement. Notification was sent to the affected resident on June 12, 2026, offering one year of identity monitoring.
- FEDERALHHS OCRas victim2024-07-09
Smith, Gambrell & Russell, LLP, a business associate, reported a hacking incident to HHS on July 9, 2024, which affected 220,000 individuals. The breach involved protected health information (PHI), including demographic, clinical, and financial data, located on a network server. In response, the firm provided notice to affected parties and implemented additional security safeguards.
- 🐻California State AGas victim2023-03-01
Smith, Gambrell & Russell, LLP experienced unauthorized access to its IT systems between July 19 and July 28, 2021. The firm discovered the incident on August 9, 2021. Documents containing personal information (names and potentially other data) of clients, primarily related to Aaron's, LLC, were exfiltrated. The firm engaged forensic investigators, reset passwords, deployed endpoint monitoring, and offered 24 months of identity theft protection via IDX. No misuse of data was indicated.
- 🦞Maine State AGas victim2023-03-01
The law firm Smith, Gambrell & Russell, LLP filed a supplemental data breach notification after an external system breach (hacking) that occurred on August 9, 2021. The breach was discovered over a year later, on October 25, 2022. The incident affected 174 Maine residents, compromising their names and driver's license or state ID numbers. The firm began notifying affected individuals between December 13, 2022, and January 13, 2023, and offered 24 months of credit monitoring and identity restoration services through IDX.
- 🍁Vermont State AGas victim2023-01-27
Smith, Gambrell & Russell, LLP notified consumers of a data breach where unauthorized access to its IT systems occurred between July 19-28, 2021. The firm discovered the incident on August 9, 2021. The breach impacted personal information, including names, of individuals whose data was held on behalf of client Aaron's, LLC. The firm engaged forensic investigators, reset passwords, and offered 24 months of identity theft protection.
- 🦫Oregon State AGas victim2023-01-11
SMITH, GAMBRELL & RUSSELL, LLP reported a data breach to the Oregon Attorney General. The breach was reported on 2023-01-11. The breach occurred during 8/9/2021. The breach was discovered on 10/25/2022. Notice was sent on 12/13/2022.
- 🌲Washington State AGas victim2022-12-13
Smith, Gambrell, & Russell, LLP, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2021-08-09 and filed notice on 2022-12-13. 545 Washington residents were affected. 491 days elapsed between awareness and notification. 21 days to identify the breach. 0 days to contain the breach.
- ⛰️New Hampshire State AGas reporting2022-12-13
Smith Gambrell & Russell, LLP (SGR) filed a supplemental notice with the New Hampshire Attorney General regarding a data breach affecting Aaron's, LLC clients. Unauthorized access occurred July 19-28, 2021. SGR discovered the incident on August 9, 2021. 170 New Hampshire residents were notified on December 13, 2022. Impacted data included names. SGR engaged forensic investigators, reset passwords, and provided credit monitoring.
- 🦞Maine State AGas victim2022-08-08
The law firm Smith, Gambrell & Russell, LLP experienced an external system breach on August 9, 2021, discovered the same day. The breach compromised the names and Social Security numbers of 19,322 individuals. The firm notified affected individuals on August 8, 2022, and offered 12 months of credit monitoring and identity restoration services through IDX.
- 🦞Maine State AGas victim2022-06-28
Smith, Gambrell, & Russell, LLP reported an external system breach (hacking) occurring on August 9, 2021. The incident compromised names and driver's license numbers of 6,515 individuals, including 1 Maine resident. Notification was sent on June 28, 2022, offering 12 months of credit monitoring and identity restoration services.
- 🦬Montana State AGas victim2022-06-28
Smith, Gambrell & Russell, LLP reported a data breach to the Montana Attorney General. The breach was reported on 2022-06-28. The breach occurred on 8/9/2021. 21 Montana residents were affected.