What Happened in the Hamill & Kaplan Data Breach?
Hamill & Kaplan, LLP, a law firm, recently notified clients about a data breach that exposed sensitive personal information. According to the notification letter, an unauthorized user broke into the firm’s computer network and accessed files containing client data. This kind of intrusion shows how even organizations trusted with highly sensitive records can fall victim to determined attackers.
The firm discovered the breach in September 2025, learning that an intruder had gained access to its network that same day. As a result, the firm moved quickly to contain the threat and secure its systems. The Hamill & Kaplan data breach notification explains that the unauthorized user was able to reach company files holding personal information belonging to clients.
Following the discovery, the firm brought in third-party IT specialists to investigate the full scope of the incident. This forensic review took time to complete, and it eventually confirmed that sensitive personal information had likely been accessible to the intruder. Because the investigation concluded well after the initial discovery, notification letters did not go out until August 2026, nearly a year after the breach occurred.
The firm also stated that it has no evidence the stolen data has actually been misused. However, it chose to notify affected individuals anyway so they could take proactive steps. In addition, the firm reported the incident to the FBI, IRS, Franchise Tax Board, and Secret Service, indicating the seriousness with which it treated the exposure.
Who was affected?
The individuals affected by this breach appear to be clients of Hamill & Kaplan, LLP, whose personal and financial information was stored on the firm’s network. Law firms often hold especially sensitive records, including tax documents, financial account details, and identification numbers, submitted by clients for legal or financial matters.
The notification letter does not state a specific number of people affected. Therefore, the total scope of this breach has not been publicly disclosed. The letter does reference concerns about tax return fraud, suggesting that at least some affected individuals may have shared tax-related documents with the firm as part of their engagement.
What Information Was Potentially Exposed?
According to the breach notification, several categories of sensitive personal data may have been accessed by the unauthorized user. This information could be extremely valuable to identity thieves and fraudsters if it falls into the wrong hands.
- Full names
- Social Security numbers
- Other government identification numbers
- Bank account information
- Other sensitive information provided to the firm
Because Social Security numbers and bank account details were involved, affected individuals face a heightened risk of identity theft and financial fraud. Criminals can use this combination of data to open new credit accounts, file fraudulent tax returns, or drain existing bank accounts. This is exactly why the firm specifically warned recipients about the possibility of tax return fraud.
Government identification numbers add another layer of risk, since they can be used to impersonate victims in ways that go beyond typical credit fraud. For example, a criminal could use this information to apply for government benefits or commit healthcare fraud under someone else’s identity. As a result, affected individuals should treat this breach as a serious threat to their financial and personal security, not a minor inconvenience.
What is the company doing?
Once Hamill & Kaplan discovered the intrusion, the firm immediately took steps to secure its network. It then hired outside cybersecurity specialists to investigate the incident thoroughly and determine exactly what happened and what data was affected.
Beyond the initial response, the firm says it continues working with cybersecurity experts to strengthen its systems and prevent future incidents. It also notified federal and state authorities, including the FBI, IRS, Franchise Tax Board, and Secret Service. In addition, the firm is offering credit monitoring services to affected individuals and has committed to alerting them if it learns of any further compromise or suspicious activity tied to their tax accounts.
What Should Affected Individuals Do?
Sign Up for Credit Monitoring and Review Your Credit Reports
Affected individuals should take advantage of the credit monitoring services offered by Hamill & Kaplan. This service can alert you quickly if someone tries to open new credit in your name.
In addition, you should request free copies of your credit reports from Experian, Equifax, and TransUnion. Reviewing these reports carefully allows you to spot unfamiliar accounts or inquiries before they cause serious damage.
Place a Fraud Alert or Credit Freeze
Because Social Security numbers and bank details were exposed, placing a fraud alert on your credit file is a smart precaution. Once one credit bureau places an alert, it must notify the other two automatically.
For even stronger protection, consider a credit freeze, which restricts access to your credit file entirely. This makes it much harder for identity thieves to open new accounts using your information, though you will need to lift the freeze temporarily when applying for credit yourself.
Get an IRS Identity Protection PIN
Given the warning about potential tax return fraud, obtaining an Identity Protection PIN from the IRS is a wise step. This PIN adds an extra layer of security when your Social Security number is used to file a tax return.
You can apply for this PIN directly through the IRS website. Once issued, the PIN prevents anyone else from filing a tax return using your Social Security number without also knowing your unique code.
Stay Alert for Phishing and Suspicious Contact
Scammers often use breach news to trick victims into revealing more information through phishing emails or calls. Consequently, you should be cautious of any unexpected messages claiming to be from the IRS, your bank, or Hamill & Kaplan itself.
Remember that the IRS never initiates contact by phone to demand money or threaten arrest. If you receive suspicious correspondence, verify it independently before responding, and report anything unusual to the firm or the appropriate authorities.
Monitor Financial Accounts and Report Fraud Promptly
Because bank account information may have been exposed, you should review your bank and financial statements regularly for unauthorized transactions. Early detection can significantly limit potential losses.
If you notice any suspicious activity, report it immediately to your bank, local law enforcement, and the Federal Trade Commission. Acting quickly gives you the best chance of reversing fraudulent charges and protecting your identity going forward.
More Information
Official data breach notification from California Attorney General
