A ransomware group called aurora claims to have stolen files from Michigan law firm Ishbia & Gagleard, P.C., exposing client Social Security numbers, tax returns, hospital records, and privileged legal files. The breach affects clients, employees, and third parties tied to the firm’s cases. Anyone notified should place a credit freeze and monitor their accounts immediately.
| Company | Ishbia & Gagleard, P.C. |
|---|---|
| Industry | Other Commercial |
| Data Types Exposed | Social Security Numbers, Protected Health Information, Client Tax Returns, Employee Files, Attorney Correspondence, Litigation Records |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware/Data Theft Extortion |
| Regulators Notified | Not Publicly Disclosed |
What Happened in the Ishbia & Gagleard Data Breach?
Ishbia & Gagleard, P.C., a Birmingham, Michigan law firm, has confirmed that criminals accessed and stole files from its network. The firm handles real estate, corporate, estate planning, personal injury, medical malpractice, and commercial litigation matters. Its clients include high-net-worth individuals and closely held businesses.
A ransomware and extortion group known as aurora has claimed responsibility for the attack. According to available evidence, the group obtained more than 360 client and matter folders. These folders reportedly contain the firm’s attorney-client privileged records, including litigation strategy memos, settlement agreements, case assessments, and correspondence with opposing counsel.
The exact timeline of the intrusion has not been publicly disclosed. However, the firm issued a notification about the incident in August 2026. As a result, affected individuals are now learning that their personal records may have been part of the stolen data.
Because law firms hold extremely sensitive records for many third parties, the investigation into this incident is complex. It likely involves forensic specialists working to determine exactly which files the attackers copied. In addition, the firm must identify every client, employee, and third party whose information appeared in the exposed folders.
Who was affected?
The Ishbia & Gagleard data breach appears to affect a wide range of people connected to the firm’s legal work. This includes current and former clients, trust beneficiaries, family members of clients, and employees of client businesses. It may also include employees of the firm itself.
The exact number of affected individuals has not been publicly disclosed. However, the exposed material reportedly includes Social Security numbers for more than 25 identified individuals. It also includes over 55 employee files tied to a sexual health clinic client, along with more than 100 client tax returns dating back to 2003.
Because the firm serves high-net-worth individuals and closely held entities, the population affected may include people with significant financial holdings and complex family or business structures. Notably, the exposed files reportedly include personal legal matters belonging to Mat Ishbia, CEO of publicly traded UWM Holdings Corp. This suggests the breach could carry outsized attention given his public profile.
What Information Was Potentially Exposed?
The scope of information involved in this incident is unusually broad for a professional services firm. This is largely because law firm files often combine legal strategy documents with the underlying personal and financial records clients submitted as evidence or for case preparation.
- Full Social Security numbers, including a scanned Social Security card
- Protected health information, including hospital admission records
- Employee files from a sexual health clinic client, including SSN searches and scanned SS cards
- Client tax returns from 2003 to 2024, including SSNs, EINs, and income data
- Litigation strategy memos, settlement agreements, and case assessments
- Correspondence with opposing counsel and internal case notes
- Email archive files containing years of attorney correspondence
- Personal legal matters connected to a prominent corporate executive
This combination of data creates serious risk. For example, a person’s Social Security number paired with tax return details and income data gives criminals nearly everything needed to open new credit accounts or file fraudulent tax returns. Because the exposure includes hospital admission records, some individuals also face the added danger of medical identity theft.
Furthermore, the presence of sensitive health clinic employee files raises unique privacy concerns. Records tied to a sexual health clinic could expose deeply personal information that individuals never intended to become public. This type of exposure can lead to targeted harassment, discrimination, or extortion attempts against the people named in those files.
What is the company doing?
Ishbia & Gagleard has notified affected individuals about the incident, consistent with its legal obligations following the discovery of unauthorized data access. The firm is working to determine the full extent of the exposed material across its client and matter files.
Because the stolen data touches so many third parties beyond the firm’s direct clients, the notification and remediation process is likely to continue for some time. The firm may need to coordinate with the hospitals and clinics referenced in the exposed records, since those organizations’ patients were also implicated. Affected individuals should watch for official letters or notices confirming whether their specific information was involved.
What Should Affected Individuals Do?
Place a Fraud Alert or Credit Freeze
Anyone whose Social Security number appears in this breach should strongly consider placing a fraud alert or credit freeze with the three major credit bureaus. A freeze restricts new lenders from accessing your credit file, which makes it much harder for criminals to open accounts in your name.
Because tax returns and EINs were also reportedly exposed, business owners among the affected group should take extra care. In addition to a personal credit freeze, consider monitoring business credit reports and alerting your bank about the potential for fraudulent account activity.
Monitor Your Credit Reports Closely
Request your free credit reports and review them for unfamiliar accounts or inquiries. Doing this regularly over the coming months is important, since stolen data is sometimes used months or even years after a breach.
If you notice any suspicious activity, report it immediately to the credit bureau and your financial institution. Keeping dated records of your review process can also help if you later need to dispute fraudulent charges.
Protect Yourself Against Medical Identity Theft
Because hospital admission records were reportedly included in the stolen files, affected individuals should also watch for signs of medical identity theft. This can include unfamiliar bills, insurance claims for care you never received, or notices from a health plan about services you don’t recognize.
Consider requesting a copy of your health insurance claims history to check for irregularities. If you spot anything unusual, report it to your insurer and healthcare provider right away to correct your medical record before it causes further harm.
Stay Alert for Phishing and Scam Attempts
Criminals who obtain stolen personal data often use it to craft convincing phishing emails, texts, or phone calls. Because this breach includes deeply personal legal and medical details, scammers may reference specific facts about your case or health history to appear credible.
As a result, treat unexpected messages referencing legal matters, medical bills, or tax issues with caution. Never click links or share personal information in response to unsolicited contact. Instead, verify the request directly with the organization using a phone number or website you already trust.
Consider Consulting a Data Breach Attorney
Given the sensitivity of the exposed records, including privileged legal files and protected health information, affected individuals may want to speak with an attorney who focuses on data breach cases. A free consultation can help clarify whether you qualify for compensation.
An attorney can also help you understand your rights under state and federal privacy laws. Because this breach touches attorney-client privilege, medical records, and financial data simultaneously, legal guidance may be especially valuable in navigating the notification and claims process.
Related Data Breaches
- McDermott Will & Schulte LLP Data Breach Exposes Social Security Numbers and Health Records
- Ocean Edge Resort and Golf Club Data Breach Exposes Social Security Numbers and Health Records
- Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) Data Breach Exposes Sensitive Law Enforcement System Data
