Borchert & LaSpina, P.C. Data Breach Exposes Passports, Driver’s Licenses and Social Security Numbers

Published: 18 August 2026
Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: August 2026

Akira ransomware attackers claim to have stolen client passports, driver’s licenses, Social Security numbers, financial records, and confidential legal files from Borchert & LaSpina, P.C., a Queens, New York law firm, with notifications issued in August 2026. Anyone who was a client of the firm should freeze their credit immediately and watch for phishing attempts referencing their legal matters.

CompanyBorchert & LaSpina, P.C.
IndustryOther Commercial
Data Types ExposedPassport Numbers, Driver’s License Numbers, Social Security Numbers, Financial Account Information, Confidential Legal Files, Contracts and Business Records
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

What Happened in the Borchert & LaSpina Data Breach?

Borchert & LaSpina, P.C., a law firm based in Queens, New York, has confirmed it was targeted in a ransomware attack. The firm handles real estate, mortgage foreclosure, commercial litigation, personal injury, and elder law matters. As a result, its case files likely contained highly sensitive client records spanning many years.

The attack has been claimed by a cybercriminal group known as Akira. This group is known for breaking into corporate networks, stealing files, and then threatening to publish stolen data unless a ransom is paid. According to the group’s own claims, they accessed client personal information, including passports, driver’s licenses, Social Security numbers, financial records, and confidential legal files.

The exact breach discovery date has not been publicly disclosed. However, the firm issued notification about the incident in August 2026. Because Akira typically infiltrates networks weeks or months before making extortion demands public, the actual intrusion may have occurred earlier than the notification date suggests.

Following discovery of the incident, Borchert & LaSpina began an investigation into the scope of the attack. Law firms handling this kind of forensic response typically work with outside cybersecurity specialists to determine which files were accessed. This process helps confirm exactly which clients and records were involved.

Who was affected?

The individuals affected likely include current and former clients of the firm. Given the firm’s focus areas, this could include people involved in real estate transactions, mortgage foreclosure proceedings, personal injury claims, and elder law matters. These case types often require clients to submit highly sensitive documents like passports and financial statements.

The exact number of people affected has not been publicly disclosed. In addition, it is not yet clear whether employees of the firm were also affected, alongside clients. Because elder law was among the firm’s practice areas, older adults may be disproportionately represented among those impacted.

The geographic scope of affected individuals appears centered on the Queens, New York area, where the firm operates. However, clients involved in real estate or legal matters sometimes reside outside the immediate region. As a result, the full geographic reach of this breach remains uncertain.

What Information Was Potentially Exposed?

According to the threat actor’s own claims, a wide range of sensitive personal and legal documents were accessed. This is especially concerning because legal files often combine several categories of identifying information in a single document.

  • Passport numbers and copies
  • Driver’s license numbers
  • Social Security numbers
  • Financial account and records information
  • Confidential legal files and case documents
  • Contracts and related business records

This combination of data creates serious risk. For example, a criminal with a passport number, driver’s license, and Social Security number can often pass identity verification checks used by banks and government agencies. This makes it easier to open new credit accounts or file fraudulent tax returns in a victim’s name.

Because legal case files were also involved, there is an added layer of risk beyond typical identity theft. Confidential legal files tied to real estate deals, foreclosures, or personal injury settlements may contain financial details, medical information, or family circumstances. If exposed publicly, this information could also lead to targeted scams, blackmail attempts, or reputational harm.

What is the company doing?

Borchert & LaSpina has acknowledged the incident and appears to be working through the process of identifying affected individuals. In response to attacks like this, firms typically shut down compromised systems, reset credentials, and bring in forensic experts to assess the damage.

Notification to affected individuals began in August 2026. Going forward, the firm will likely continue to notify newly identified individuals as the investigation progresses. Firms in this situation often also offer credit monitoring or identity protection services to affected clients, though no specific offering has been publicly confirmed in this case.

What Should Affected Individuals Do?

Place a Fraud Alert or Credit Freeze

Because Social Security numbers, passports, and driver’s licenses were reportedly exposed, affected individuals should strongly consider placing a credit freeze with all three major credit bureaus. A freeze prevents most lenders from accessing your credit file, which stops criminals from opening new accounts in your name.

Alternatively, a fraud alert is a lighter-weight option that still requires creditors to verify your identity before extending credit. This can be done for free by contacting any one of the three bureaus, since they are required to notify the other two. Given the sensitivity of the data involved here, a freeze offers stronger protection.

Monitor Your Credit Reports Closely

Affected individuals should request free copies of their credit reports and review them for unfamiliar accounts or inquiries. You can get free weekly reports from all three major bureaus through AnnualCreditReport.com.

In addition, consider signing up for a credit monitoring service if one is offered by the firm. Because stolen identity documents can be used months or even years after a breach, ongoing monitoring is more effective than a one-time check.

Watch for Phishing and Impersonation Attempts

Criminals often use stolen personal information to craft convincing phishing emails or phone calls. For example, a scammer might reference your real legal case details to appear legitimate while requesting payment or additional personal information.

Because of this, treat unexpected calls, texts, or emails referencing your legal matters with caution. Never provide personal information or payment details to anyone who contacts you unexpectedly, even if they seem to know specifics about your case.

Protect Your Identity Documents

Since passport and driver’s license numbers were reportedly exposed, consider contacting the relevant issuing agencies to ask about fraud flags or replacement options. The U.S. Department of State can provide guidance if you believe your passport information has been compromised.

Similarly, your state’s Department of Motor Vehicles may offer guidance on monitoring for fraudulent use of your driver’s license number. Taking these steps early can help limit the damage if someone attempts to use your identity documents fraudulently.

Consult a Data Breach Attorney

Given the sensitivity of the exposed information, affected individuals may want to speak with an attorney who focuses on data breach cases. An attorney can help you understand whether you qualify for compensation and what steps to take next.

Many data breach attorneys offer free initial consultations. This makes it a low-risk way to learn more about your legal options, especially if you experience financial losses or identity theft linked to this incident.



Related Data Breaches

See the latest data breaches we're tracking →