The GrayRobinson 2025 data breach involved unauthorized access to the Florida-based law firm’s network from March 5 through March 24, 2025 and a determination that certain files may have been accessed or removed. The Indiana Attorney General’s current 2026 report lists 80,383 affected people, including 234 Indiana residents.
According to GrayRobinson’s official notice, the firm detected unauthorized network access on or about March 24, 2025, secured its network, reported the matter to law enforcement, and began an investigation with external cybersecurity professionals. The file review was completed on April 13, 2026, and individual notifications began on April 24, 2026.
How Was the GrayRobinson Breach Confirmed?
The primary source is GrayRobinson’s own incident notice. The firm directly states the access window, detection date, response steps, result of the file review, and data fields that varied by person. The notice establishes that the event was more than suspicious traffic: it says affected files may have been accessed or removed by the unauthorized individual or individuals.
The Indiana Attorney General’s current year-to-date breach report lists GrayRobinson P.A., gives March 5, 2025 as the breach start, April 24, 2026 as the notification date, and reports 234 Indiana residents and 80,383 total affected people. The HHS Office for Civil Rights portal separately lists the firm as a Business Associate, reports 54,131 people, and classifies the event as a Hacking/IT Incident involving a Network Server. The organization notice, state regulator, and federal health record therefore provide complementary confirmation.
What Happened From March 5 Through March 24, 2025?
GrayRobinson’s official statement says unauthorized access to its network occurred between March 5 and March 24, 2025. The firm detected the incident on or about March 24. Its investigation found that some files may have been accessed or removed during that period, but the public notice does not identify the exploited vulnerability, initial access method, responsible party, or whether any files were later published.
The public sources do not characterize the event as ransomware and do not attribute it to a named threat group. The HHS classification uses the terms Hacking/IT Incident and Network Server. This entry consequently describes a confirmed network intrusion and possible file access or removal without adding an unverified technique, ransom demand, or dark-web publication claim.
What Personal and Health Information Was Involved?
GrayRobinson says the information varied by individual and may have included one or more of the following: first and last name, date of birth, Social Security number, driver’s license number, state or government identification, financial account information, medical information, and health insurance information. The notice does not say that every affected person had every category in their files.
A Social Security number combined with government identification can raise the risk of account-opening fraud or impersonation. Financial account information can support account fraud, while medical and insurance details can enable medical-identity misuse or highly convincing targeted messages. Because an individual notice identifies which fields apply to its recipient, that specific letter should control over the general list.
How Should the Counts of 80,383 and 54,131 Be Read?
In the Indiana Attorney General’s accessible current report, 80,383 is expressly labeled as the total affected population and 234 is the Indiana resident count. An older Indiana view previously showed a total of 65,113, but the current report raises the entry to 80,383. This record therefore uses the regulator’s latest explicit overall total rather than the earlier value.
The HHS portal’s 54,131 figure is the number separately reported through the federal HIPAA breach program and is 26,252 below the Indiana total. HHS is a health-regulatory report, while Indiana provides a distinct overall-total column. Because the sources do not explain whether the difference reflects population scope, reporting obligations, or update timing, the values are not added and the HHS figure does not replace the nationwide total.
How Did GrayRobinson Respond?
The firm says it secured its network, reported the event to law enforcement, and worked with external cybersecurity professionals experienced in incident response. It then conducted a detailed review of potentially affected information. After completing that review on April 13, 2026, GrayRobinson began notifying people whose information may have been in the files on April 24.
A sample notice says the firm had no evidence as of the notice date that information had been used for financial fraud or identity theft and offered eligible recipients complimentary monitoring through Experian IdentityWorks. That statement does not guarantee that future misuse will not occur. GrayRobinson also says it continues to evaluate and modify its practices and internal controls, although the public notice does not describe the technical changes.
What Should Affected People Do?
A recipient should first check the letter for the data fields that apply to them and the enrollment deadline for any complimentary service. If a Social Security number or government identifier was involved, review reports from the three credit bureaus and consider a free fraud alert or credit freeze. If financial account information was listed, monitor transactions and changes to contact details.
People whose letters identify medical or health-insurance information can review explanation-of-benefits statements and patient portals for an unfamiliar service, procedure, or provider. Do not share a password, payment detail, or one-time code in an unexpected message using the GrayRobinson name. The incident response line is 844-403-4596, available Monday through Friday from 9:00 a.m. to 6:30 p.m. Eastern; verify the number on the firm’s current official notice before calling.