Herbert Smith Freehills Kramer Data Breach Exposes Social Security Numbers and Health Records

Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: July 2026

What Happened in the Herbert Smith Freehills Kramer Data Breach?

Herbert Smith Freehills Kramer LLP, a large international law firm, filed a notice with the Vermont Attorney General’s Office confirming a data breach. The filing, submitted in late July 2026, disclosed that sensitive personal information tied to some of the firm’s clients had been compromised. This filing is what brought the incident into public view.

According to the regulatory submission, the exposed data includes Social Security numbers, government identification numbers, and health records. The firm classified the incident under Vermont’s Other Commercial reporting category. However, the filing does not explain how the intrusion happened, when it was first discovered internally, or what technical failure allowed it to occur.

Vermont’s public disclosure system no longer posts the full consumer notification letters that would normally include those extra details. As a result, the exact timeline of the intrusion, its discovery, and the firm’s internal response remain unclear to the public. Because the underlying breach date has not been released, only the date of the regulatory filing itself is confirmed right now.

Herbert Smith Freehills Kramer was created through a 2025 combination of two established firms: Herbert Smith Freehills, based in the United Kingdom, and Kramer Levin Naftalis & Frankel, based in the United States. Together they formed a sprawling legal practice with roughly 2,700 lawyers spread across 26 offices worldwide. This scale means the firm manages an enormous volume of sensitive files for clients across many industries and jurisdictions.

No forensic details about attacker identity or method have been made public so far. This page will be updated if the firm releases more specifics, or if additional states publish notification letters with more complete information.

Who was affected?

The Vermont filing states that four Vermont residents had their personal information compromised in this incident. Those individuals appear to be clients or contacts of the firm, though the filing does not specify whether they were direct clients, opposing parties, or other individuals connected through litigation or transactional work.

It’s important to note that four is only the count reported to Vermont specifically. Because Herbert Smith Freehills Kramer operates globally, the total number of people affected across all states and countries has not been publicly disclosed. Law firms often hold data belonging to people who never directly interacted with the firm, including opposing parties, witnesses, or family members named in legal proceedings.

Given the presence of health records among the exposed data, it’s possible some affected individuals were involved in matters touching on medical issues, such as personal injury, employment, or insurance disputes. Because the firm has not released a demographic breakdown, whether minors are among the affected individuals also remains unknown at this time.

What Information Was Potentially Exposed?

The Vermont filing identifies three broad categories of compromised data. This combination is especially serious because each category enables a different form of fraud, and together they create layered risk for affected individuals.

  • Social Security numbers
  • Government identification numbers
  • Health records

The filing does not specify which particular health details were involved, nor does it confirm whether financial account numbers were also exposed. Anyone who eventually receives a direct notification letter should review it closely, since it may list data categories specific to their own record that weren’t captured in the state-level summary.

Social Security numbers and government ID numbers, when combined, give criminals nearly everything needed to open new credit accounts, file fraudulent tax returns, or construct a synthetic identity using a real person’s information. Unlike a password, a Social Security number cannot simply be reset. This means the exposure creates a risk that can linger for years, long after the breach itself fades from headlines.

Health record exposure introduces a separate danger: medical identity theft. Criminals can use stolen health information to obtain prescription drugs, receive medical treatment, or submit fraudulent insurance claims under someone else’s name. This type of fraud can be particularly hard to detect because it may not show up on a standard credit report, and it can even corrupt a victim’s actual medical history.

What is the company doing?

Herbert Smith Freehills Kramer met its legal obligation by reporting the breach to Vermont’s Attorney General, which is a required step under the state’s data breach notification law. Beyond that filing, the firm has not publicly detailed what technical or procedural remediation it has undertaken since discovering the incident.

It also remains unclear whether the firm is offering credit monitoring or identity protection services to affected individuals. Because Vermont no longer publishes full notification letters, details like these typically only reach the people directly affected. Anyone who receives a letter from the firm should read it in full, since it may describe specific protections being offered at no cost.

As more information emerges from other state filings or from the firm itself, this article will be updated to reflect newly confirmed facts about remediation efforts, notification timing, and any protective services made available to affected clients.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Affected individuals should request copies of their credit reports from all three major bureaus and review them for unfamiliar accounts or inquiries. Because Social Security numbers were exposed, new-account fraud is a realistic concern that can take months to surface.

Consumers are entitled to a free credit report from each bureau annually, and many bureaus now offer additional free monitoring tools. Checking these reports every few months, rather than just once, gives a better chance of catching fraud early before it causes lasting damage.

Place a Fraud Alert or Credit Freeze

Given that Social Security numbers and government ID numbers were both compromised, placing a credit freeze with Equifax, Experian, and TransUnion is one of the strongest protective steps available. A freeze blocks new creditors from accessing your credit file, which makes it much harder for a criminal to open accounts in your name.

Alternatively, a fraud alert requires creditors to take extra verification steps before extending credit. This option is less restrictive than a freeze but still adds a meaningful layer of protection. Either step can typically be set up online or by phone in a matter of minutes.

Watch for Signs of Medical Identity Theft

Because health records were part of this breach, affected individuals should also review any explanation-of-benefits statements from their health insurer. Unfamiliar charges or services listed on these statements could indicate that someone is using stolen health information fraudulently.

If anything looks unfamiliar, contact your insurer immediately to dispute the charge and request a corrected record. Catching medical fraud early helps prevent inaccurate information from becoming permanently embedded in your medical history.

Stay Alert for Phishing Attempts

Scammers frequently exploit news of real breaches to send fake notification emails or text messages. These messages often impersonate the breached company in an attempt to trick recipients into handing over even more personal information.

Therefore, anyone who receives a message referencing this breach should verify its authenticity independently. Avoid clicking embedded links or calling phone numbers listed in an unsolicited message, and instead contact the firm directly using a number you find on your own.

Consider Filing Your Taxes Early

Because a stolen Social Security number can be used to file a fraudulent tax return, filing your own return as early as possible reduces this risk. Once a legitimate return is on file with the IRS, it becomes much harder for a criminal to file a fraudulent one afterward.

If you suspect tax-related fraud has already occurred, contact the IRS promptly and consider requesting an Identity Protection PIN for future filing seasons. This added step can help block fraudulent returns before they’re processed.



Related Data Breaches

See the latest data breaches we're tracking →