[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2g4ufnr21g4w4":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"6a6fe16504b1a1824674c5be","FriedFrank2025","Fried Frank Data Breach","fried-frank-2025","friedfrank.com","2025-10-23T00:00:00.000Z","2026-08-03T00:31:33.108Z","2026-08-03T00:34:48.193Z","Personal-data breach reported to the Texas Attorney General and corroborated by independent reporting","https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage",[15,17,18],"https:\u002F\u002Fwww.securityweek.com\u002Fafter-goldman-jpmorgan-discloses-law-firm-data-breach\u002F","https:\u002F\u002Fwww.friedfrank.com\u002F",179613,"known",null,"people","High",[25,26,27,28,29,30,31,32],"Names","Physical addresses","Social security numbers","Driver's licenses","Government-issued identification","Financial information","Medical information","Dates of birth","\u003Cp>\u003Cstrong>The 2025 Fried Frank data breach\u003C\u002Fstrong> was a security incident involving systems at the international law firm and personal information belonging to 179,613 people. The Texas Attorney General places the incident between October 23 and October 28, 2025.\u003C\u002Fp>\u003Cp>Fried, Frank, Harris, Shriver &amp; Jacobson LLP is a US-based law firm working across corporate law, finance, real estate and disputes. The regulator record identifies the organization at its New York address, while the firm's official domain is friedfrank.com.\u003C\u002Fp>\u003Ch2>How was the incident confirmed?\u003C\u002Fh2>\u003Cp>Texas Attorney General record BR-0004892 publishes the organization identity, incident and discovery dates, affected information types, total population and consumer notification methods.\u003C\u002Fp>\u003Cp>SecurityWeek's report, which includes a statement from Fried Frank, says an unauthorized third party copied files from the firm's shared network drive. The statement says the incident was contained, outside security specialists were engaged and the matter was reported to law enforcement.\u003C\u002Fp>\u003Ch2>When did the incident occur?\u003C\u002Fh2>\u003Cp>According to the official entry, the unauthorized access began on October 23, 2025 and ended on October 28. The firm discovered the incident on October 27, 2025, and the Texas entry was published on March 9, 2026.\u003C\u002Fp>\u003Cp>Public information does not explain how the initial access was obtained, which vulnerability may have been used or who was behind the incident. The entry therefore does not present an initial access method, technical root cause or threat actor as established facts.\u003C\u002Fp>\u003Ch2>What information was affected?\u003C\u002Fh2>\u003Cp>The Texas record lists names, physical addresses, Social Security numbers, driver's license numbers, government identification numbers such as passports or state IDs, financial information, medical information and dates of birth.\u003C\u002Fp>\u003Cp>The filing also includes an unspecified “other” information category. The same fields should not be assumed to apply to every person, and public sources do not identify the field combination for each affected individual.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The Texas Attorney General record reports a nationwide total of 179,613 people. The 16,724 Texas residents in the same entry are included within that total and should not be added separately.\u003C\u002Fp>\u003Cp>Independent reporting identifies 659 people in a narrower group connected to a JPMorgan investment fund. That limited figure should not be treated as a separate amount that increases the nationwide total for the same incident.\u003C\u002Fp>\u003Ch2>What are the potential risks?\u003C\u002Fh2>\u003Cp>Names, addresses, dates of birth and Social Security numbers can be combined for identity theft, fraudulent account opening and targeted phishing. Financial information also warrants close review of bank and card activity.\u003C\u002Fp>\u003Cp>Government identification numbers can remain useful for a long time, so the risk is not limited to the period immediately after the incident. Medical information also creates privacy concerns and may support highly personalized fraud attempts.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should regularly review credit reports, new-account inquiries, bank activity and card statements. Credit freezes or fraud alerts can be considered, and unfamiliar activity should be reported promptly to the relevant institution.\u003C\u002Fp>\u003Cp>Unexpected links claiming to come from Fried Frank, a bank, an investment firm or a government agency should be verified independently through a known official channel. Do not provide identity, account or health information through unsolicited communications.\u003C\u002Fp>","","Fried Frank Data Breach (179.6 Thousand People Affected)","The Fried Frank data breach affected 179,613 people and involved identity, financial and medical information. Review the timeline, data types and safety steps.","\u002Fuploads\u002Flogo\u002Ffried-frank-official.webp",false,{"name":40,"sector":41,"country":42,"website":10,"websiteArchiveUrl":34,"websiteStatus":43,"websiteCheckedAt":12},"Fried Frank","Business Services","United States","active; access restricted from the verification environment"]