SMITH GAMBRELL & RUSSELL LLP
ent_ca22cf2746749b228b26d7fd
Disclosures
19
State AG · HHS OCR · 12 jurisdictions
Multi-filing incidents
7
incidents joining 2+ filings here
Max affected reported
220,000
nationwide · HHS OCR GA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SMITH GAMBRELL & RUSSELL LLP
- Normalized
- smith gambrell russell— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300N24MY7YQHNQC78
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- sgrlaw.com
Disclosure history (19)newest first
- Massachusetts State AGas reporting2026-07-06
T.A. Solberg Co., Inc. reported unauthorized network access on March 3, 2026, affecting 6 Massachusetts residents. The incident involved the viewing of personal and protected health information. The company engaged a cybersecurity firm, took systems offline, and provided 24 months of identity monitoring to affected individuals. Notification was filed with the Massachusetts AG on July 3, 2026.
- Rhode Island State AGas reporting2026-06-24
AssuranceAmerica Managing General Agency, LLC notified the Rhode Island Attorney General of a cybersecurity incident affecting 631 RI residents. Malicious activity targeted an employee on March 16, 2026, leading to unauthorized access and data copying. Affected data included names, contact info, insurance policy details, and driver's license numbers. The company engaged forensic specialists, notified law enforcement, reset credentials, and isolated systems. Notifications to individuals are scheduled by July 30, 2026.
- New Hampshire State AGas reporting2026-06-23
AssuranceAmerica Managing General Agency, LLC notified the New Hampshire Attorney General of a data security incident affecting 462 NH residents. The breach involved unauthorized access to IT systems following a targeted phishing attack on an employee on March 16, 2026. Data copied included names, contact info, insurance policy details, and driver's license numbers. The company engaged forensic specialists, notified law enforcement, reset credentials, and implemented enhanced security controls including XDR monitoring and MFA.
- New Hampshire State AGas reporting2026-06-19
Kentucky Mountain Health Alliance, Inc. (KMHA) notified the NH Attorney General of a data breach affecting one New Hampshire resident. On or around September 16, 2025, KMHA identified unauthorized access to its network. An investigation determined an unauthorized individual viewed and obtained files containing PHI, SSNs, driver's license numbers, financial account info, and medical information. KMHA took systems offline, engaged a cybersecurity firm, and notified law enforcement. The affected resident was notified on June 12, 2026, and offered one year of complimentary identity monitoring services through Epiq.
- New Hampshire State AGas reporting2025-04-10
Avpro, Inc. notified the NH AG of a March 8, 20225 breach where an unauthorized third party accessed IT systems. Personal info of 2 NH residents (including SSNs, DOBs, health insurance data) was exposed. Avpro took servers offline, moved to Microsoft cloud, implemented MFA and encryption, and offered credit monitoring.
- GEORGIAHHS OCRas victim2024-07-09
Smith, Gambrell & Russell, LLP, a business associate, reported a hacking incident to HHS on July 9, 2024, which affected 220,000 individuals. The breach involved protected health information (PHI), including demographic, clinical, and financial data, located on a network server. In response, the firm provided notice to affected parties and implemented additional security safeguards.
- California State AGas victim2023-03-01
Smith, Gambrell & Russell, LLP experienced unauthorized access to its IT systems between July 19 and July 28, 2021. The firm discovered the incident on August 9, 2021. Documents containing personal information (names and potentially other data) of clients, primarily related to Aaron's, LLC, were exfiltrated. The firm engaged forensic investigators, reset passwords, deployed endpoint monitoring, and offered 24 months of identity theft protection via IDX. No misuse of data was indicated.
- Maine State AGas victim2023-03-01
The law firm Smith, Gambrell & Russell, LLP filed a supplemental data breach notification after an external system breach (hacking) that occurred on August 9, 2021. The breach was discovered over a year later, on October 25, 2022. The incident affected 174 Maine residents, compromising their names and driver's license or state ID numbers. The firm began notifying affected individuals between December 13, 2022, and January 13, 2023, and offered 24 months of credit monitoring and identity restoration services through IDX.
- South Carolina State AGas reporting2023-01-30
Aaron's, LLC notified via South Carolina AG that an unauthorized person accessed IT systems between July 19-28, 2021. Smith, Gambrell & Russell, LLP discovered the incident on August 9, 2021. Customer names were potentially exposed. Aaron's determined PII was involved after reviewing documents on November 16, 2022. Notices sent December 13, 2022.
- Vermont State AGas victim2023-01-27
Smith, Gambrell & Russell, LLP notified consumers of a data breach where unauthorized access to its IT systems occurred between July 19-28, 2021. The firm discovered the incident on August 9, 2021. The breach impacted personal information, including names, of individuals whose data was held on behalf of client Aaron's, LLC. The firm engaged forensic investigators, reset passwords, and offered 24 months of identity theft protection.
- Oregon State AGas victim2023-01-11
SMITH, GAMBRELL & RUSSELL, LLP reported a data breach to the Oregon Attorney General. The breach was reported on 2023-01-11. The breach occurred during 8/9/2021. The breach was discovered on 10/25/2022. Notice was sent on 12/13/2022.
- Washington State AGas reporting2022-12-13
Aaron's, LLC reported a data breach affecting 516 Washington residents. Documents containing PII (names, SSNs, driver's licenses, medical info) were taken from law firm Smith, Gambrell & Russell's IT systems between July 19-28, 2021. The firm discovered the incident on August 9, 2021, and notified Aaron's in October 2022. Notifications were sent on December 13, 2022, offering 24 months of credit monitoring.
- New Hampshire State AGas reporting2022-12-13
Smith Gambrell & Russell, LLP (SGR) filed a supplemental notice with the New Hampshire Attorney General regarding a data breach affecting Aaron's, LLC clients. Unauthorized access occurred July 19-28, 2021. SGR discovered the incident on August 9, 2021. 170 New Hampshire residents were notified on December 13, 2022. Impacted data included names. SGR engaged forensic investigators, reset passwords, and provided credit monitoring.
- GEORGIAHHS OCRas victim2022-09-28
Smith, Gambrell & Russell, LLP reported to HHS on 2022-09-28 a Hacking/IT Incident affecting 4,688 individuals. Breached information located on Network Server. PHI included demographic, clinical, and financial information.
- Maine State AGas victim2022-08-08
The law firm Smith, Gambrell & Russell, LLP experienced an external system breach on August 9, 2021, discovered the same day. The breach compromised the names and Social Security numbers of 19,322 individuals. The firm notified affected individuals on August 8, 2022, and offered 12 months of credit monitoring and identity restoration services through IDX.
- Massachusetts State AGas victim2022-07-06
Smith, Gambrell & Russell, LLP reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-07-06. 760 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2022-06-28
Smith, Gambrell, & Russell, LLP reported an external system breach (hacking) occurring on August 9, 2021. The incident compromised names and driver's license numbers of 6,515 individuals, including 1 Maine resident. Notification was sent on June 28, 2022, offering 12 months of credit monitoring and identity restoration services.
- Indiana State AGas victim2022-06-28
Smith, Gambrell & Russell LLP reported a data breach to the Indiana Attorney General. 1,558 Indiana residents were affected. 6,515 individuals affected in total.
- Montana State AGas reporting2022-06-28
Smith, Gambrell & Russell, LLP notified clients of GEICO that unauthorized access to IT systems on August 9, 2021 may have exposed personal information including names, driver's license numbers, and addresses. The firm engaged forensic specialists and law enforcement, implemented enhanced security controls, and offered identity theft protection services.