GrayRobinson P.A. reported a data breach to the Montana Attorney General. The breach was reported on 2026-04-24. The breach occurred from 03/05/2025 to 05/24/2025. 41 Montana residents were affected.
Affected (this filing): 41
Clustered 8 filings across 6 jurisdictions · filing window Apr 24, 2026 → May 7, 2026. View entity profile → Other incidents for this victim →
incident inc_aeecbdf9321245ad · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA FL IN MT NH VT
HHS OCR · State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
8 filings across 6 jurisdictions · Apr 24, 2026 – May 7, 2026 · 3 milestones
Mar 5, 2025
When the intrusion reportedly occurred, per the linked filings
Mar 24, 2025
Reported by CALIFORNIA AG filings
Apr 13, 2026
Reported by NEW HAMPSHIRE AG filings
GrayRobinson P.A. reported a data breach to the Montana Attorney General. The breach was reported on 2026-04-24. The breach occurred from 03/05/2025 to 05/24/2025. 41 Montana residents were affected.
Affected (this filing): 41
GrayRobinson, P.A. reported to HHS on 2026-04-24 a Hacking/IT Incident affecting 54,131 individuals. Breached information located on Network Server. GrayRobinson, P.A. is identified as a Business Associate.
Affected (this filing): 54,131
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
GrayRobinson, P.A. detected unauthorized access to its network on March 24, 2025. The incident involved potential exposure of personal information, including full names and Social Security numbers, for individuals whose data may have been accessed between March 5, 2025, and March 24, 2025. The firm secured its network, reported the incident to law enforcement, and engaged external cybersecurity professionals. Affected individuals are being offered complimentary credit monitoring services.
GrayRobinson P.A. reported a data breach to the Indiana Attorney General. The breach occurred on 2025-03-05 and was reported on 2026-04-24. 221 Indiana residents were affected. 65,113 individuals affected in total.
Affected (this filing): 65,113
GrayRobinson, P.A. notified the New Hampshire Attorney General of a cybersecurity incident affecting 34 NH residents. Unauthorized access occurred between March 5, 2025, and March 24, 2025. GrayRobinson discovered the breach on April 13, 2026, after a forensic investigation. Impacted data included names, DOB, medical info, financial account info, driver's license numbers, and SSNs. GrayRobinson secured the network, reported to law enforcement, and offered 12 months of credit monitoring. Notification letters were mailed on April 24, 2026.
Affected (this filing): 34
GrayRobinson, P.A. detected unauthorized access to its network on March 24, 2025. Investigation determined files may have been accessed or removed between March 5 and March 24, 2025. Affected data includes full name and Social Security numbers. The firm secured the network, reported to law enforcement, engaged external cybersecurity professionals, and offered complimentary identity monitoring services.
GreyRobinson, P.A. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-05-05. The reporting organization type is Other Commercial. 26 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit or Debit Account Info, Health Records.
GrayRobinson, P.A., a law firm, notified the New Hampshire Attorney General that an unauthorized actor accessed its network between March 5 and March 24, 2025. GrayRobinson discovered the breach on April 13, 2026, after a forensic investigation. The incident potentially exposed personal information, including names, DOBs, SSNs, driver's license numbers, financial account info, and medical data, for 41 New Hampshire residents. GrayRobinson reported the incident to law enforcement, engaged external cybersecurity professionals, and is offering one year of complimentary credit monitoring to affected residents.
Affected (this filing): 41