Law Firm Data Breach: Blank Rome LLC 

Law Firm Data Breach: Faces Class-Action Lawsuits 

Blank Rome LLC, a law firm in Philadelphia, Pennsylvania, is facing two proposed class-action lawsuits following a cyber incident that exposed the personal information of more than 57,000 current, former, and prospective clients. The breach occurred in May when a cybercriminal posing as the firm’s IT department tricked one of the attorneys into uploading files to an external file-hosting website.  

The exposed data includes sensitive information like names, Social Security numbers, addresses, phone numbers, email addresses, birthdates, taxpayer ID numbers, driver’s license and passport numbers, financial account details, medical information, and health insurance data. The firm stated that there was no access to the firm’s network and no disruption to operations.  

Allegations in the Lawsuits 

As per the plaintiffs, Blank Rome LLC negligently failed to protect private information and breached duties under common law, contract law, industry standards, the Federal Trade Commission Act, and HIPAA. Some additional claims include negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, breach of confidence, and violations of California-specific privacy and consumer protection laws, such as the California Consumer Privacy Act and the California Customer Records Act. 

Class members are reported to have suffered a range of harms, including invasion of privacy, lost time, emotional distress, out-of-pocket expenses, increased spam communications, reduced value of personal data, and heightened risk of fraud or identity theft. 

Financial Implications and Relief Sought 

The plaintiffs are seeking compensatory, punitive, and statutory damages, restitution, equitable and injunctive relief, attorneys’ fees and costs, and pre- and post-judgment of interest. The scale of the breach was enormous, and the value of the personal information involved could result in significant financial exposure if the case proceeds. 

Context and Industry Perspective 

Blank Rome LLC is not the first law firm to face litigation following a data breach. Other firms, such as Wiley Rein LLP, Fried, Frank, Harris, Shriver & Jacobson LLP, and Pillsbury Winthrop Shaw Pittman LLP, have faced similar lawsuits. These cases highlight something crucial, which is the growing importance of cyber risk management and adequate professional liability coverage for law firms.  

Lessons for Law Firms 

  • Cybersecurity Awareness: Staff must be trained to recognize phishing attempts and impersonation scams.  
  • Data Handling Policies: With strict protocols set in place for sensitive client information, the risk of accidental exposure is reduced.  
  • Insurance and Risk Management: Cyber Liability and Professional Liability coverages are essential to be maintained, especially to mitigate financial exposure in the event of a breach.  
  • Incident Response Planning: A clear and well-drafted plan must be in place to respond to breaches, including notification procedures and forensic investigation. This can limit damage and support compliance within organizations.  

This incident underscores the high stakes of client data protection and demonstrates that even highly reputable firms are vulnerable to sophisticated social engineering attacks.

For more information, contact us today.