Confirmed breach. Intrusion Feb 6, 2025, discovered Apr 6, 2026 — the first regulatory filing landed 25 days later. 34,161 individuals reported across the linked filings.
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
State AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedhigh sensitivity
Affected (total reported)
34,161
Data types
5
PII · PHI · Identity (basic)
Jurisdictions
6
CA IN MA ME NH VT
Linked filings
6
all State AG
Sensitive data
identity_government
Affected residents by state
per-filing reported counts
IN34,153
ME34,153
NH8
State AGs report only their own residents; bars show per-filing counts.
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Feb 6, 2025
When the intrusion reportedly occurred, per the linked filings
424 days
Breach discovered
Apr 6, 2026
Reported by NEW HAMPSHIRE AG filing
6 State AG filingsMay 1, 2026 – May 8, 2026ExpandCollapse
Berger & Williams, LLP, a law firm, disclosed a cybersecurity incident in Massachusetts (Case 2026-695). The breach involved unauthorized access to personal and health information. The firm has revised security practices, implemented additional measures, and established a toll-free response line for affected individuals.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
🏎️Indiana State AGlinked via multistate filing link · 100%
Berger & Williams LLP reported a data breach to the Indiana Attorney General. The breach occurred on 2025-02-06 and was reported on 2026-05-04. 28 Indiana residents were affected. 34,153 individuals affected in total.
Affected (this filing): 34,153
🦞Maine State AGlinked via multistate filing link · 100%
Berger & Williams, LLP (a San Diego law firm) reported a data breach to the Maine Attorney General via outside counsel McDonald Hopkins. The breach occurred on 02/06/2025 and affected 34,153 individuals total, including 3 Maine residents. The notice description was 'Other' and the information acquired field was left blank in the Maine portal entry; however, the linked notification letter is titled 'Letter_A_Adult_SSN_Final_v3_Redacted.pdf', strongly suggesting Social Security Numbers were among the affected data elements. Consumer notifications were sent electronically on 05/04/2025, and 12 months of identity theft and credit monitoring through TransUnion was offered. The discovery date listed ('04-06-2026') appears to be a data-entry error in the source filing.
Affected (this filing): 34,153
🍁Vermont State AGlinked via multistate filing link · 100%
Berger & Williams reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-05-05. The reporting organization type is Other Commercial. 6 Vermont residents were affected. Categories of data breached: Social Security Numbers.
🐻California State AGlinked via multistate filing link · 100%
California SB-24 breach notice sample submitted by law firm Berger & Williams, LLP, dated February 6, 2025. The redacted notification letter (filename indicates 'Adult_SSN') references protections including fraud alerts, security freezes, and free credit reports, and includes guidance on protecting health information — implying that affected data likely included Social Security numbers and possibly health/medical information. The notice does not disclose root cause, threat actor, attack vector, or the number of individuals affected; the substantive incident-description sections of the letter are not present in the extracted text (only generic boilerplate appears). Filed with the California Attorney General pursuant to Cal. Civ. Code §1798.29/1798.82.
⛰️New Hampshire State AGlinked via multistate filing link · 100%
Berger & Williams, LLP, a law firm, notified the New Hampshire Attorney General of unauthorized access to an employee email account affecting approximately 8 NH residents. The breach occurred around February 6, 2025, and was discovered on April 6, 2026. Personal information, including names and Social Security numbers, was accessed. Notifications were sent on May 4, 2026, offering one year of credit monitoring and fraud insurance.