Hamill & Kaplan Data Breach Exposes Social Security Numbers and Bank Details

Other Commercial data breach illustration
Breach Discovery: September 2025Breach Notification: August 2026

What Happened in the Hamill & Kaplan Data Breach?

Hamill & Kaplan, LLP, a law practice in Westlake Village, California, has begun alerting clients that someone broke into its computer systems without permission. The firm says this intruder was able to reach files holding private client details. As a result, names, Social Security numbers, and banking information may have fallen into the wrong hands.

The firm found the intrusion on a single day in September 2025, and it later determined the attacker had gotten into the network that very same day. Investigators have not said how the attacker first broke in. However, Hamill & Kaplan moved to lock down its systems once it spotted the problem, then brought in outside digital forensics experts to dig into what actually happened.

That investigation took a long stretch of time to finish. Notification letters to clients did not go out until August 2026, roughly eleven months after the firm first noticed the breach. Hamill & Kaplan says the delay came from the depth of the forensic review needed to figure out precisely which files and clients were touched.

Because law firms often sit on years of sensitive case records, this kind of incident raises particular concern. The firm also looped in law enforcement, notifying the FBI, the IRS, the California Franchise Tax Board, and the U.S. Secret Service. Importantly, the firm stated that no law enforcement request pushed back the timeline for telling clients.

Who was affected?

The people affected are current or former clients of Hamill & Kaplan who shared personal or financial records with the firm during legal representation. Because law firms typically gather deep financial and identifying detail from clients, the pool of exposed information can be unusually sensitive compared with a typical retail or service breach.

Hamill & Kaplan has not shared a specific number of affected clients, either nationally or within California. Therefore, anyone who has worked with this firm should watch for an official notification letter rather than assume they are unaffected. The firm has also not detailed whether minors’ information was involved in any client files.

What Information Was Potentially Exposed?

According to the notification letter Hamill & Kaplan filed with the California Attorney General’s Office, several categories of sensitive personal data were potentially reached by the intruder. This is the kind of information that, once exposed, can follow a person for years if not properly monitored.

  • Full names
  • Social Security numbers
  • Other government-issued identification numbers
  • Bank account information
  • Other sensitive personal details clients had shared with the firm

When Social Security numbers and bank details are exposed together, the danger goes well beyond a single stolen password. Criminals can use this combination to open new credit lines, file fraudulent tax returns, or drain existing bank accounts. This is precisely why the firm specifically warned clients to watch their tax records closely.

In addition, because government-issued ID numbers were also involved, victims could face attempts at benefits fraud or fake account creation using their identity. Because this data does not expire or change like a password does, the exposure window for harm can stretch on for months or even years after the incident. As a result, vigilance now matters just as much as it will later.

What is the company doing?

Once Hamill & Kaplan discovered the intrusion, the firm said it acted immediately to secure its network from further unauthorized access. It then engaged third-party IT specialists to run a full forensic investigation into the scope of the compromise. This process is what the firm says accounted for much of the nearly year-long gap before notification.

The firm also reported the incident to multiple federal and state authorities, including the FBI, IRS, California’s Franchise Tax Board, and the U.S. Secret Service. Beyond that outreach, Hamill & Kaplan sent notification letters to affected individuals and filed a copy with the California Attorney General’s Office in August 2026. The firm has stated it has no current evidence that the exposed data has actually been misused.

What Should Affected Individuals Do?

Monitor Your Financial Accounts and Credit Reports

Anyone who received a letter from Hamill & Kaplan should start checking bank and credit card statements on a regular basis. Look closely for charges or withdrawals you don’t recognize, even small ones, since fraudsters sometimes test accounts with tiny transactions first.

In addition, pull your free credit reports from all three major bureaus and review them for unfamiliar accounts. Because Social Security numbers were involved here, new fraudulent accounts opened in your name are a real possibility. Catching this early makes cleanup far easier.

Consider a Fraud Alert or Credit Freeze

Given that Social Security numbers and bank information were both potentially exposed, placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion is a smart precaution. A freeze blocks new creditors from accessing your credit file, which makes it much harder for anyone to open accounts in your name.

While a freeze takes a few extra steps when you need to apply for credit yourself, it offers strong protection during a period like this. You can lift it temporarily whenever you need to apply for a loan or new account, then reinstate it afterward.

Watch for Tax-Related Fraud

Because Hamill & Kaplan specifically flagged tax fraud as a risk, affected clients should pay close attention to any notices from the IRS or state tax agencies. If someone else tries to file a return using your Social Security number, the IRS will typically flag the duplicate filing and contact you.

To stay ahead of this, consider requesting an Identity Protection PIN from the IRS, which prevents anyone else from filing a tax return in your name without that unique code. Filing your own return early in tax season can also reduce the chance that a fraudster beats you to it.

Stay Alert for Phishing Attempts

After a breach like this, scammers often follow up with phishing emails or phone calls pretending to be from the breached company, a bank, or even a government agency. These messages may try to trick you into revealing more personal details or clicking malicious links.

Never click links or provide information in response to an unexpected message. Instead, contact the organization directly using a phone number or website you already know to be legitimate. This simple habit blocks most phishing attempts before they can do damage.

Keep Your Notification Letter and Consider Legal Options

If you received a letter from Hamill & Kaplan, hold onto it along with any related correspondence. This documentation can serve as proof that your information was involved if you later decide to pursue legal action or file an identity theft report.

Because law firms are expected to maintain strong safeguards over client data, affected individuals may have legal options worth exploring. Speaking with a data breach attorney for a free case evaluation can help you understand whether you qualify for compensation.



More Information

Official data breach notification from California Attorney General

Related Data Breaches

Browse all recent data breaches →