Charles E. Tabor AAL LLC Data Breach Claim: Client Files and SSNs Reportedly Exposed

Published: 11 October 2026
Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: October 2026

A ransomware group claims to have stolen roughly 96,456 files from law firm Charles E. Tabor AAL LLC, allegedly including Social Security numbers, medical records, and signed settlement checks tied to client legal cases. The firm has not confirmed this breach. Anyone who has worked with this firm should monitor their credit reports and watch for suspicious account activity right away.

CompanyCharles E. Tabor AAL LLC
IndustryOther Commercial
Data Types ExposedSocial Security Numbers, Medical Records, Driver’s License Numbers, Tax Forms, Settlement Check Images, HIPAA Authorization Forms, Client Case Files
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Charles E. Tabor AAL LLC Data Breach?

A ransomware group has posted claims that it stole a large volume of files from Charles E. Tabor AAL LLC, a law firm. According to the group’s own listing, the stolen data totals roughly 96,456 files and about 114.5 GB. The firm has not publicly confirmed this incident, so the details below reflect only what the threat actor has claimed.

Based on the claims, the alleged theft includes an extensive archive of client case files. This appears to span many years of legal work, consolidated into fewer large files rather than scattered records. Because the firm has not issued a statement, the exact method of intrusion and timeline remain unknown. The notification date associated with this incident is October 2026, which is when public reporting of the claim emerged.

No independent forensic confirmation has been made public at this time. As a result, it is not yet clear whether the firm has launched its own investigation, hired a cybersecurity firm, or notified law enforcement. Readers should treat the specifics as allegations until Charles E. Tabor AAL LLC releases an official statement or notification letter. However, the nature of the claimed data, which includes sensitive legal and medical files, warrants real concern regardless of confirmation status.

Who was affected?

The individuals potentially affected appear to be current and former clients of the firm, based on the claimed data. This includes people involved in personal injury, insurance, and settlement cases. Because law firms often represent clients across state lines, the geographic scope of those affected is not limited to one area.

The claimed files reportedly reference specific settlement cases, including one involving a minor. This raises the possibility that children’s personal information was included in the exposed files. The exact number of individuals affected has not been publicly disclosed. Therefore, anyone who has worked with this firm on a legal claim should consider themselves potentially impacted until more information becomes available.

What Information Was Potentially Exposed?

The ransomware group’s claims describe a wide range of sensitive documents tied to legal and insurance cases. If accurate, this would represent a significant trove of personal and financial data. Below is a summary of the data categories referenced in the claim.

  • Full client database with personal identifying information across multiple cases
  • Hospital and insurance scans tied to numerous legal matters
  • Medical scans and HIPAA authorization forms
  • Driver’s licenses and identification documents, including those of minors
  • Tax forms containing Social Security numbers
  • A state death certificate used as a legal exhibit
  • Signed settlement releases and endorsement authorizations
  • Scanned settlement checks showing signatures and bank routing details

If these claims are accurate, the risk to affected individuals would be substantial. Social Security numbers combined with names and tax documents create a strong foundation for identity theft. Criminals could use this combination to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name.

In addition, the claimed exposure of signed settlement checks with signatures and MICR line details is particularly concerning. This type of information could allow criminals to attempt check fraud or create counterfeit checks. Furthermore, medical scans and HIPAA forms could be misused for medical identity theft, including fraudulent insurance claims filed under a victim’s name.

What is the company doing?

Because Charles E. Tabor AAL LLC has not publicly confirmed this incident, there is no confirmed information about remediation steps, investigation status, or notification plans. No public statement from the firm has been identified describing credit monitoring, identity protection services, or law enforcement involvement.

As a result, affected individuals should not assume that notification letters or protective services are forthcoming until the firm issues an official statement. If the firm does confirm the breach and offers remediation steps, this article will reflect updated information as it becomes available. In the meantime, individuals who worked with this firm should take proactive steps on their own.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Because the claimed data includes Social Security numbers and tax documents, affected individuals should request free copies of their credit reports. You can get these from each of the three major credit bureaus. Review each report carefully for accounts or inquiries you do not recognize.

In addition, consider setting up ongoing credit monitoring if you are not already using a service. This can alert you quickly if someone attempts to open new credit in your name. Early detection often makes a significant difference in limiting financial damage.

Consider a Credit Freeze or Fraud Alert

Given the alleged exposure of Social Security numbers, placing a credit freeze with each bureau is a strong protective step. A freeze blocks new creditors from accessing your credit file, which makes it much harder for identity thieves to open accounts in your name.

Alternatively, a fraud alert requires creditors to take extra verification steps before approving new credit. This is a lighter-touch option than a freeze. Either way, acting quickly reduces the window of opportunity for criminals to exploit your information.

Watch for Medical and Insurance Fraud

Because the claimed data includes hospital scans, insurance records, and HIPAA forms, affected individuals should review medical bills and insurance statements closely. Look for treatments or claims you do not recognize. This could indicate someone is using your identity for medical services.

If you notice suspicious activity, contact your insurance provider and healthcare providers immediately. Request an accounting of disclosures if needed. Reporting errors quickly can prevent long-term complications with your medical records and insurance coverage.

Be Alert to Phishing and Check Fraud Attempts

Since the claimed data reportedly includes scanned settlement checks with signatures and banking details, affected individuals should monitor their bank accounts closely. Watch for unauthorized withdrawals or unfamiliar checks clearing against your account. Contact your bank promptly if anything looks unusual.

Additionally, be cautious of emails, texts, or calls referencing your legal case or settlement. Scammers often use stolen details to craft convincing phishing messages. Never click links or share personal information in response to unsolicited communications, even if they reference accurate case details.

Consult a Data Breach Attorney

Given the sensitivity of the claimed data, affected individuals may want to speak with an attorney who focuses on data breach cases. An attorney can help determine whether you have grounds for legal action if the breach is confirmed. Many offer free initial consultations.

Moreover, a knowledgeable attorney can help you understand your rights and any applicable deadlines. Because this incident remains unconfirmed, staying informed about updates is important. A free case evaluation can help clarify your options without any upfront cost.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Browse all recent data breaches →