Mogren, Glessner & Ahrens, P.S. Data Breach Exposes Personal and Financial Information

Published: 18 September 2026
Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Mogren, Glessner & Ahrens, P.S., a law firm, confirmed unauthorized access to files containing personal information and notified the Washington State Attorney General in September 2026. The exact number of affected individuals and full scope of exposed data have not been publicly disclosed. Anyone connected to the firm should monitor credit reports and consider a credit freeze immediately.

CompanyMogren, Glessner & Ahrens, P.S.
IndustryOther Commercial
Data Types ExposedFull Names, Social Security Numbers, Financial Account Information, Personal Identifying Information
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedWashington State Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Mogren, Glessner & Ahrens, P.S. Data Breach?

Mogren, Glessner & Ahrens, P.S. recently confirmed that unauthorized parties gained access to sensitive files held by the firm. As a result, the law firm submitted a formal notification to the Washington State Attorney General in September 2026. This filing confirmed that personal information tied to individuals connected to the firm’s records had been compromised.

The exact date the intrusion first began has not been publicly disclosed. However, the firm’s notification indicates that files containing personal data were accessed without authorization before the breach was identified. Because law firms often store highly sensitive records, including case files, financial documents, and identifying information, this type of incident can carry significant consequences for the people named in those files.

Following discovery of the incident, the firm reportedly took steps to investigate the scope of the intrusion. This likely included working to determine which systems were accessed and which individuals had information involved. As is standard after this kind of event, the firm proceeded to notify the appropriate state regulator once its review reached a point where notification was warranted.

Details about the specific method of attack have not been made public. Nonetheless, the firm’s regulatory filing makes clear that the access was unauthorized and that personal information was involved. Additional facts may emerge as the investigation continues or as further notices are issued to affected individuals.

Who was affected?

The population affected by this breach has not been fully detailed in public records. In general, incidents at law firms tend to affect current and former clients whose case files were stored electronically. In addition, employees of the firm could also have personal information stored in internal systems that may have been touched by the same intrusion.

The exact number of individuals affected by the Mogren, Glessner & Ahrens, P.S. data breach has not been publicly disclosed. Because the firm filed with the Washington State Attorney General, it is reasonable to assume that at least some affected individuals reside in Washington state. However, given that law firms often represent clients from multiple states, the geographic reach of this breach could extend further.

It is not yet known whether minors are among those affected. Similarly, there is no confirmation of whether the exposed data belongs primarily to clients, employees, or both. Anyone who has worked with this firm, either as a client or in another capacity, should consider themselves potentially affected until more specific information becomes available.

What Information Was Potentially Exposed?

While the complete list of compromised data elements has not been fully itemized in public materials, breaches involving law firms commonly expose a range of sensitive categories. Because legal files often include financial and identifying records used in litigation, estate planning, or business transactions, the risk of highly sensitive data exposure is significant.

  • Full names
  • Social Security numbers
  • Financial account information
  • Other personal identifying details contained in client or case files

If Social Security numbers were part of the exposed data, affected individuals face a heightened risk of identity theft. Criminals can use this information to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. This type of fraud can take months to detect and even longer to fully resolve.

In addition, exposure of financial account details could lead to direct fraud on existing accounts. As a result, affected individuals should watch their bank and credit card statements closely. Because law firm records sometimes contain especially sensitive personal history, there is also a risk that exposed information could be used for targeted scams or blackmail attempts.

What is the company doing?

In response to the breach, Mogren, Glessner & Ahrens, P.S. filed formal notification with state regulators, a step required under most state breach notification laws. This action indicates that the firm has completed at least an initial assessment of the incident and determined that notification obligations applied. The firm also filed a report with the Washington State Attorney General, dated September 3, 2026.

Beyond the regulatory filing, further remediation steps have not been publicly detailed. Firms in this situation typically work to secure affected systems, review access controls, and assess whether additional safeguards are needed going forward. Affected individuals should watch for a direct notification letter from the firm, which may include more specific information about the data involved and any protective services being offered.

Monitor Your Credit Reports

Anyone connected to this breach should begin monitoring their credit reports right away. This is one of the simplest and most effective ways to catch fraudulent activity early. You can request free credit reports from all three major bureaus and review them for unfamiliar accounts or inquiries.

Because identity thieves often wait before using stolen data, ongoing monitoring is important, not just a one-time check. Consider setting up recurring reviews every few months. If you notice anything suspicious, report it to the credit bureau immediately and consider filing a police report.

Consider a Credit Freeze or Fraud Alert

Given the possibility that Social Security numbers and financial information were exposed, placing a credit freeze is a strong protective step. A freeze prevents new creditors from accessing your credit file, which makes it much harder for criminals to open accounts in your name. This service is free and can be requested through each credit bureau individually.

Alternatively, a fraud alert offers a lighter form of protection. It requires creditors to take extra verification steps before granting credit in your name. Because a fraud alert lasts for a limited time, you may need to renew it periodically until you feel the risk has passed.

Watch for Phishing and Scam Attempts

Following a data breach, scammers often use exposed information to craft convincing phishing emails, texts, or phone calls. Therefore, treat any unexpected communication requesting personal details with suspicion, even if it appears to come from a trusted source. Legitimate organizations rarely ask for sensitive information through unsolicited messages.

If you receive a suspicious message referencing this breach, avoid clicking links or providing any information. Instead, verify the request by contacting the organization directly through a known phone number or website. Reporting phishing attempts can also help authorities track broader scam campaigns tied to this incident.

Review Financial and Legal Accounts Regularly

Because this breach involves a law firm, affected individuals should also review any accounts tied to legal or financial matters handled by the firm. This includes checking for unauthorized changes to estate documents, business filings, or financial arrangements set up through the firm. Early detection can prevent more serious complications later.

In addition, keep records of any communication you receive from the firm regarding this incident. These records may become useful if you need to demonstrate financial harm or pursue a claim later. Consulting with a data breach attorney can help clarify your options if you experience losses tied to this exposure.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

Official data breach notification report (PDF) from Washington State Attorney General

Related Data Breaches

View the full list of tracked data breaches →