The WilmerHale 2026 data breach occurred when a member of personnel at the international law firm provided personal information on May 8, 2026 to a third party who falsely represented that they were authorized to receive it. The firm's official consumer letter explains that the event was an isolated disclosure caused by identity deception rather than direct access to its systems.
Current Texas Attorney General record BR-0005169 reports that 4,711 people across the United States were affected, including 436 Texas residents. The confirmed information types are names and Social security numbers, and the fields may have varied by person.
How Was the WilmerHale Breach Confirmed?
The primary incident source is WilmerHale's sample consumer letter dated July 10, 2026 and published in the California Attorney General archive. It directly confirms the May 8 event, identity misrepresentation, investigation with outside forensic specialists, notification to federal law enforcement, possible information fields, and the Experian protection service offered.
The second official source is Texas Attorney General data security breach record BR-0005169. It identifies the organization by its full legal name and Washington address and publishes the incident date, June 25 discovery or determination date, nationwide total, Texas subset, mailed-notice method, and name and SSN categories. Reuters independently reported the incident and the subsequent proposed federal class action on July 15.
What Happened on May 8, 2026?
According to WilmerHale, a member of personnel supplied personal information to someone who falsely claimed to be authorized to receive it. The firm promptly began an investigation, retained leading forensic experts, and notified federal law-enforcement authorities. Its review determined that the event was isolated and that the third party did not directly access the firm's systems.
That distinction matters: the public letter does not describe malware, ransomware, exploitation of a vulnerability, persistent network access, or a broad system intrusion. It does clearly confirm that the disclosure was unauthorized. The actor's identity, communication channel, impersonated role, and details used to persuade the employee were not published.
What Information Was Affected?
The official letter says the information was obtained while WilmerHale provided certain legal services and may have included a name and Social Security number. The Texas record lists the same two principal categories. Both fields should not be assumed for every person; a direct individual notice is the best source for the recipient-specific scope.
A name combined with an SSN creates long-term risk of new-account fraud, tax-identity misuse, benefits fraud, and convincing targeted messages. Public sources do not separately identify addresses, birth dates, driver's licenses, passports, bank accounts, payment cards, passwords, medical information, or legal-file contents as confirmed fields for this event.
How Many People Were Affected?
Texas Attorney General record BR-0005169 publishes an exact nationwide total of 4,711 people and a Texas subset of 436. The Texas figure is included within the nationwide population and is not added again. The record was published in the state portal on July 14, 2026 and matches WilmerHale's full legal name.
Some early secondary summaries show a smaller total assembled from state filings available at the time. The current official Texas record provides the broader nationwide scope, so 4,711 is used. Lawsuit allegations reported by Reuters do not represent a separate incident or an additional affected population; they concern the same May 2026 event and remain unproven in court.
How Did WilmerHale Respond?
WilmerHale said it promptly opened an investigation, worked with outside forensic experts, and notified federal law enforcement. The firm concluded that the third party did not directly access its systems, that the incident was isolated, and that it was unaware of further disclosure or misuse as of the letter date. That time-bound finding does not eliminate the possibility of later misuse.
Affected people received a notice dated July 10, 2026 and were offered 24 months of complimentary Experian IdentityWorks credit monitoring and identity-theft protection. The letter gives an enrollment deadline of October 30, 2026 at 11:59 p.m. UTC. The service includes credit monitoring, identity restoration, extended restoration support, and conditional identity-theft insurance; recipients must use their individual activation code.
What Should Affected People Do?
Recipients should enroll in the Experian offer only through the official link and code in their own letter, review reports from all three credit bureaus, and consider a free credit freeze or fraud alert when an SSN was involved. Unfamiliar credit inquiries, new accounts, tax notices, and identity-verification requests should be investigated promptly through a known channel for the relevant organization.
Be cautious with unexpected messages invoking WilmerHale, Experian, a court, or a government agency. A message containing a real name, case detail, or service relationship is not automatically legitimate. Do not disclose an SSN, activation code, or one-time code; open the institution's address manually instead of following an inbound link and report suspected misuse through IdentityTheft.gov and the relevant financial institution.