What Happened in the Bergeson, LLP Data Breach?
Bergeson, LLP is a litigation law firm headquartered in San Jose, California. In August 2026, the firm began sending letters to individuals warning them that a security incident may have exposed some of their personal information. This is the Bergeson LLP data breach now drawing attention from former clients and other affected parties.
The firm has not publicly explained how the incident happened. It also has not shared exactly when the intrusion occurred or when it was first discovered internally. Instead, the notification letters simply carry a date of early August 2026, which is when recipients were formally told about the situation.
A notice was also filed with the Massachusetts Attorney General’s office around the same time the letters went out. That filing states that Bergeson, LLP is reviewing its internal policies and adding new security measures in response to the event. However, the filing stops short of naming a root cause, such as hacking, an insider incident, or a vendor compromise.
Because law firms hold enormous amounts of sensitive material tied to litigation, this kind of gap between discovery and full public disclosure is common. Firms often must notify regulators and consumers within a set legal window, even before a forensic review is complete. As a result, early notices like this one frequently describe an incident without fully detailing its scope or cause.
Who Was Affected?
The people affected by this incident appear to include clients of Bergeson, LLP. However, law firms also routinely store information belonging to opposing parties, witnesses, and other individuals connected to litigation matters. This means some recipients of the notification letter may never have been direct clients of the firm at all.
The exact number of people affected by the Bergeson LLP data breach has not been publicly disclosed. Because litigation records can span years and multiple case types, the population impacted could include individuals from a wide range of legal matters. At this time, there is no public confirmation regarding the geographic reach of those affected beyond the notice filed in Massachusetts.
It also remains unclear whether minors, employees, or other third parties connected to legal proceedings are among those notified. Given the nature of litigation files, family law, estate matters, and business disputes often involve dependents or related parties whose information gets swept into case records.
What Information Was Potentially Exposed?
Bergeson, LLP has not publicly listed the specific categories of personal information involved in this incident. That said, the firm is offering 24 months of free credit monitoring through TransUnion, which is a detail worth paying attention to. This type of offer is typically extended when identifying information, such as Social Security numbers, may have been part of the exposure.
- Full names
- Potentially Social Security numbers or other government-issued identification numbers
- Case-related or litigation records
- Financial account details that may appear in legal filings
- Other personal identifiers commonly held by law firms
Because the firm has not confirmed the exact data categories, affected individuals should treat this notice with caution. If sensitive identifiers like Social Security numbers were involved, the risk of long-term identity theft increases substantially. Criminals can use this kind of information to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name.
In addition, litigation files sometimes contain deeply personal details, including financial disputes, medical information tied to injury claims, or family circumstances. If any of that material was part of the exposure, affected individuals could also face targeted phishing attempts that reference real case details to appear more convincing. This makes vigilance especially important in the months ahead.
What Is the Company Doing?
In response to the incident, Bergeson, LLP has begun notifying individuals whose information may have been affected. The firm filed formal notice with the Massachusetts Attorney General’s office, which is a step required under state breach notification laws when residents are impacted.
Beyond notification, the firm says it is reviewing its existing security policies and procedures. According to the filed notice, this review is meant to identify and implement additional safeguards going forward. As part of its response, Bergeson, LLP is also offering affected individuals 24 months of complimentary credit monitoring through TransUnion, along with a 90-day window to enroll.
What Should Affected Individuals Do?
Enroll in the Free Credit Monitoring
If you received a letter from Bergeson, LLP, you should sign up for the complimentary TransUnion credit monitoring right away. This service can help you catch suspicious account activity before it turns into a larger financial problem.
Because the offer includes a 90-day enrollment window, don’t wait to act. Missing the deadline could mean losing access to a protection that costs nothing and takes only a few minutes to set up.
Consider a Credit Freeze or Fraud Alert
Given that credit monitoring was offered, it’s wise to also consider placing a fraud alert or a full credit freeze on your credit file. A freeze makes it much harder for identity thieves to open new accounts using your information, since lenders generally cannot access your frozen file without your explicit approval.
You can request a freeze directly with Equifax, Experian, and TransUnion. Because each bureau operates separately, you’ll need to contact all three to be fully protected.
Monitor Financial Accounts and Credit Reports Closely
In addition to enrolling in monitoring, review your bank and credit card statements regularly for unfamiliar charges. Even small, unrecognized transactions can be an early warning sign of misuse.
You’re also entitled to a free credit report from each of the three major bureaus through annualcreditreport.com. Checking these reports periodically helps you spot new accounts or inquiries that you didn’t authorize.
Stay Alert for Phishing Attempts
Because this breach involves a law firm, scammers may try to use real case details to make phishing emails or calls seem legitimate. Be cautious of any unexpected messages referencing legal matters, especially those asking for personal or financial information.
If you’re ever unsure whether a message is genuine, contact the firm directly using a phone number you find independently, rather than one provided in the suspicious message. This simple step can prevent you from handing over sensitive details to a scammer.
Report Suspicious Activity and Know Your Options
If you notice signs of identity theft, report it promptly to local law enforcement and your state Attorney General’s office. Acting quickly can limit the damage and create a paper trail that helps resolve fraudulent activity faster.
You may also want to speak with a data breach attorney to understand whether you have legal options related to this incident. An attorney can help you evaluate potential compensation and walk you through the claims process at no upfront cost.
