Molod Spitz & DeSantis Data Breach Exposes Client Names and Personal Information

Other Commercial data breach illustration
Breach Discovery: June 2026Breach Notification: July 2026

What Happened in the Molod Spitz & DeSantis Data Breach?

Molod Spitz & DeSantis, P.C., a law firm headquartered in New York City, has told a group of individuals that their personal information may have been caught up in a network intrusion. The firm sent notification letters in July 2026 after determining that files stored on its systems held personal details belonging to the people it contacted. This event is now known as the Molod Spitz & DeSantis data breach, and it raises fresh concerns about how well law firms guard the sensitive records they keep on behalf of clients.

According to the firm’s own account, an unauthorized party may have gained entry to its network and accessed certain files around August 2025. However, the firm did not identify who was behind the intrusion or how the attacker initially broke in. This gap between the suspected access date and the eventual notice is common in cases like this, since confirming exactly whose data was touched takes time.

Molod Spitz & DeSantis says it brought in outside cybersecurity specialists once it learned something was wrong. Together, they carried out a forensic investigation paired with a manual review of documents. As a result of that work, the firm concluded in June 2026 that specific files contained personal information tied to the individuals it later notified.

Because law firms retain case files for years after a matter closes, the review process often stretches across many months. Investigators must reconstruct what was accessed, match affected files to current contact records, and confirm mailing addresses before letters can go out. This lengthy process explains much of the ten-month span between the suspected intrusion and the final notification.

Who was affected?

The people affected by this incident are clients of Molod Spitz & DeSantis, P.C. whose personal information was stored in the firm’s case files. The firm has not publicly disclosed how many individuals received notice, so the total number of affected clients remains unknown at this time.

Because law firms often hold records for former as well as current clients, the affected population could include people whose legal matters concluded long ago. In addition, since the firm has not detailed the nature of every legal matter involved, it’s possible that both individuals and representatives of businesses were among those notified. Anyone who worked with the firm around or before August 2025 should treat the notice seriously, even if their case seems unrelated to the type of information typically targeted in cyberattacks.

What Information Was Potentially Exposed?

The firm’s notification letter confirms that affected files contained each recipient’s full name. It also states that additional personal information was involved, though it does not spell out exactly what that means. Because the full list of exposed data categories was not shared publicly, individuals should assume more sensitive details might be part of the exposure.

Based on the type of information law firms typically collect for legal matters, the exposed data could reasonably include:

  • Full name
  • Contact information such as address or phone number
  • Social Security numbers, if collected for a legal matter
  • Financial account details related to litigation or settlements
  • Case-specific records tied to the individual’s legal matter
  • Other personal identifiers not specifically disclosed by the firm

When a law firm’s files are compromised, the risk goes beyond simple identity theft. For example, litigation records sometimes include settlement amounts, medical details, or financial disclosures that were never meant for public view. If any of that information reached an unauthorized party, affected individuals could face targeted scams that reference specific facts about their legal matter, making the fraud attempt seem more convincing.

In addition, if Social Security numbers or financial account numbers were part of the exposed files, victims could face a heightened risk of new account fraud, fraudulent tax filings, or unauthorized charges. Because the firm has not ruled out these categories, affected individuals should treat this breach with the same caution they would apply to any breach involving financial and identity-related data.

What is the company doing?

Once Molod Spitz & DeSantis learned of the security incident, it launched an investigation and brought in outside cybersecurity professionals to determine what happened. This response led to the forensic review and manual document check that ultimately identified which individuals had personal information in the affected files. The firm then began sending written notification letters in July 2026 to the people it identified.

As a precaution, the firm is offering complimentary credit monitoring services through Epiq – Privacy Solutions ID to those affected. It has stated that it currently has no evidence that any exposed information has been misused for identity theft or financial fraud. Even so, offering monitoring services suggests the firm recognizes the potential for future harm and wants to give recipients a tool to catch suspicious activity early.

What Should Affected Individuals Do?

Enroll in Credit Monitoring

Anyone who received a notification letter should sign up for the complimentary credit monitoring being offered through Epiq – Privacy Solutions ID. This service can alert you quickly if someone tries to open new credit accounts using your information.

Because enrollment deadlines typically apply, it’s best to act as soon as you receive your letter rather than setting it aside. Waiting too long could mean missing the window to activate this free protection entirely.

Consider a Fraud Alert or Credit Freeze

Given that this breach may have involved Social Security numbers or financial details, placing a fraud alert with Equifax, Experian, or TransUnion is a smart next step. A fraud alert requires lenders to take extra steps to verify your identity before opening new credit in your name.

For even stronger protection, you can place a security freeze on your credit files. This makes it much harder for anyone, including you, to open new credit until the freeze is lifted, so it offers a higher level of security for anyone worried about identity theft.

Watch for Phishing and Scam Attempts

Scammers often use publicized data breaches as bait, sending emails or texts that appear to come from the breached company or its credit monitoring provider. Because this breach involved a law firm, phishing messages might reference a specific legal matter to seem more believable.

As a result, you should never click links or share personal details in response to unexpected messages about this breach. Instead, contact Molod Spitz & DeSantis directly using verified contact information if you have questions about your notification letter.

Monitor Your Financial Accounts Regularly

In addition to credit monitoring, you should personally review your bank and credit card statements for any unfamiliar charges. Catching fraud early can limit the financial damage and make disputing charges much easier.

You can also request a free copy of your credit report at annualcreditreport.com to check for accounts you don’t recognize. Reviewing your report periodically over the coming months is a good habit, since fraudulent activity doesn’t always appear right away.

Consult a Data Breach Attorney

Because the exact scope of exposed information remains unclear, some affected individuals may want to speak with an attorney who handles data breach cases. A lawyer can help you understand your legal options and whether you may be entitled to compensation.

Many law firms offer free consultations for data breach matters, so reaching out costs nothing and carries no obligation. This step can be especially useful if you later discover signs of identity theft or fraud tied to this incident.



Related Data Breaches