Davis & Ferber LLP, a New York law firm, suffered a ransomware attack by the Akira group, which claims to have stolen 60GB of data including SSNs, passports, driver’s licenses, and court records for nearly 1,000 people. The firm notified affected individuals in August 2026. Anyone affected should place a credit freeze and monitor accounts immediately.
| Company | Davis & Ferber LLP |
|---|---|
| Industry | Other Commercial |
| Data Types Exposed | Social Security Numbers, Passport Numbers, Driver’s License Numbers, Birth and Death Certificates, Phone Numbers, Court Filings and Hearing Records, Police Reports |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
What Happened in the Davis & Ferber Data Breach?
Davis & Ferber LLP, a New York law firm, has confirmed a serious cybersecurity incident. The firm handles personal injury, medical malpractice, nursing home abuse, and family law matters. As a result, it stores highly sensitive client records tied to ongoing and past legal cases.
A ransomware group known as Akira claimed responsibility for the attack. According to the group’s own statements, attackers accessed and copied roughly 60 gigabytes of corporate data. This included detailed personal information belonging to nearly a thousand people connected to the firm’s cases.
The exact date the intrusion began has not been publicly disclosed. However, the firm issued notification about the incident in August 2026. Because law firms hold extremely sensitive litigation files, this breach carries added weight beyond typical corporate data theft.
Following discovery of the incident, Davis & Ferber began an investigation to determine the scope of the compromise. Cybersecurity investigations of this type typically involve forensic review of network logs, isolation of affected systems, and confirmation of what data the attackers actually accessed. As of now, the firm has not released a detailed public timeline explaining exactly when the unauthorized access first occurred.
Who was affected?
The breach appears to primarily affect current and former clients of Davis & Ferber LLP. Given the firm’s practice areas, this likely includes people involved in personal injury claims, medical malpractice lawsuits, nursing home abuse cases, and family law disputes.
According to the threat actor’s claims, close to a thousand individuals had personal data included in the stolen files. This number has not been independently confirmed by the firm as of this writing. Because family law and injury cases often involve minors, dependents, or vulnerable adults, some affected individuals could include people who never directly interacted with the firm as clients themselves.
The geographic scope of those affected is likely concentrated in New York, given the firm’s location. Still, personal injury and malpractice clients sometimes reside outside the state, so the true reach of this breach may extend further. The firm has not disclosed a full breakdown of affected individuals by location or case type.
What Information Was Potentially Exposed?
The threat actor claims to have obtained an unusually broad set of sensitive documents. Because this data comes directly from legal case files, it likely includes both personal identifiers and confidential litigation materials.
- Full names and addresses
- Social Security numbers
- Passport numbers
- Driver’s license numbers
- Birth and death certificates
- Phone numbers
- Court filings and hearing records
- Police reports
- Non-disclosure agreements and other confidential files
This combination of data creates significant identity theft risk. For example, a person’s Social Security number paired with their driver’s license number and address gives criminals nearly everything needed to open new credit accounts. Passport numbers can also be used to attempt fraudulent applications for benefits or travel documents.
Beyond financial fraud, this breach carries unusual privacy risks because of the legal nature of the stolen files. Court records, police reports, and case-related documents can reveal deeply personal details about medical conditions, family disputes, or abuse allegations. As a result, affected individuals may face reputational or emotional harm in addition to standard identity theft threats.
What is the company doing?
In response to the incident, Davis & Ferber has begun working to determine the full extent of the exposure. Law firms facing this type of attack typically bring in outside cybersecurity specialists to assess damage and secure their networks going forward.
The firm issued breach notifications in August 2026 to inform potentially affected individuals. Notification letters of this kind generally explain what data was involved and outline any protective steps being offered. It has not been publicly disclosed whether Davis & Ferber is providing credit monitoring or identity protection services to affected individuals at this time.
Because the attackers claim to still hold copies of the stolen files, the firm may also be taking steps to monitor for any public release or sale of the data. This kind of ongoing threat monitoring is common after ransomware incidents involving extortion demands.
What Should Affected Individuals Do?
Place a Fraud Alert or Credit Freeze
Anyone whose Social Security number or driver’s license number may have been exposed should strongly consider placing a fraud alert or credit freeze. This step makes it much harder for criminals to open new accounts using stolen identity information.
To do this, contact one of the three major credit bureaus: Equifax, Experian, or TransUnion. A freeze at one bureau typically triggers a notification to the other two. Because freezes are free and reversible, this is one of the strongest protective steps available to affected individuals.
Monitor Your Credit Reports Closely
Affected individuals should request free copies of their credit reports and review them for unfamiliar accounts or inquiries. Regular monitoring helps catch fraudulent activity early, before it causes lasting financial damage.
In addition, consider signing up for ongoing credit monitoring if it becomes available through the firm. Even without a formal offer, many credit bureaus and financial institutions provide free monitoring tools that can flag suspicious activity quickly.
Watch for Phishing and Scam Attempts
Because this breach exposed names, phone numbers, and case details, affected individuals may become targets of highly convincing phishing attempts. Scammers often use real personal details to make fraudulent messages seem legitimate.
Be cautious of unexpected calls, emails, or texts referencing your legal case or personal information. Never click links or share additional personal details in response to unsolicited messages. Instead, contact the firm directly through a verified phone number if you have concerns.
Protect Sensitive Documents Like Passports and Certificates
Because passport numbers and birth or death certificates were reportedly exposed, affected individuals should consider additional precautions. For example, monitoring for unauthorized passport applications or unusual government correspondence can help catch misuse early.
If you suspect your passport information was compromised, consider contacting the U.S. Department of State for guidance. Keeping copies of official identity documents and tracking any unexpected renewal or replacement notices can also help detect fraud early.
Consult a Data Breach Attorney
Given the sensitivity of the exposed legal and personal records, affected individuals may want to speak with an attorney who focuses on data breach cases. A free consultation can help clarify whether you qualify for compensation.
Because this breach involves a law firm’s own client files, the situation carries unique legal considerations. An experienced attorney can help evaluate potential claims and explain your rights moving forward.
