ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Blank Rome hit with twin class actions over data breach affecting more than 57,000 clients

Blank Rome LLP, an Am Law 100 firm with 800 attorneys across 16 offices in the United States and abroad, was sued twice on Monday over a May data breach that plaintiffs say exposed the personal information of more than 57,000 current and former clients.


The separate complaints, filed in the U.S. District Court for the Eastern District of Pennsylvania by plaintiffs Laura Delapaz and Anthony Santana, accuse the firm of negligence in safeguarding sensitive records and argue it violated obligations under common law, contract law, industry standards, the Federal Trade Commission Act and the Health Insurance Portability and Accountability Act.


Delapaz, a California resident, said in her filing that she was among 57,554 current, former and prospective Blank Rome clients whose data was compromised. Her complaint alleges the firm took more than a month to notify affected individuals after the May 21 breach and that the exposed information included names, birth dates, addresses and taxpayer identification numbers.


The complaints from Delapaz and Santana describe a broader set of compromised data, including Social Security numbers, email addresses, phone numbers, driver’s license numbers, state ID card numbers, passport numbers, financial account numbers, payment card information, medical information and health insurance information.


Blank Rome has said the breach stemmed from a social-engineering scheme in which a cybercriminal impersonated the firm’s information technology department and persuaded an attorney to upload files to an outside file-hosting site. The firm has said the incident did not involve access to its internal network or any disruption to its operations, and it has characterized the episode as a limited incident.


"We believe the lawsuit has no merit and will aggressively defend against it," the firm said in a statement. The lawsuits allege Blank Rome failed to adequately train employees on cybersecurity and did not maintain reasonable safeguards to prevent the intrusion.


According to the complaints, affected individuals have suffered harm including invasion of privacy, lost time and expenses spent responding to the breach, emotional distress, a rise in unsolicited communications, diminished value of their personal data and heightened exposure to fraud and identity theft.


Delapaz and Santana are each seeking to represent a nationwide class of individuals whose information was exposed in the breach. Their complaints, which are nearly identical, raise claims of negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty and breach of confidence, along with alleged violations of California’s Unfair Competition Law, the California Consumer Privacy Act and the California Customer Records Act. The plaintiffs are asking for compensatory, punitive and statutory damages, along with restitution, injunctive relief, attorneys’ fees and costs, and pre- and post-judgment interest.


Blank Rome joins a lengthening roster of law firms confronting litigation tied to cyberattacks. Fox Rothschild, Wiley Rein, Pillsbury Winthrop Shaw Pittman, Kelley Drye, and Fried, Frank, Harris, Shriver & Jacobson have all faced similar suits in the past year, while firms including Gunster Yoakley & Stewart, Orrick Herrington & Sutcliffe and Bryan Cave Leighton Paisner have resolved comparable claims through settlements.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543