American law firm GrayRobinson said it suffered a significant data security incident last year that compromised the sensitive personal data of over 65,000 individuals.

American law firm GrayRobinson said it suffered a significant data security incident last year that compromised the sensitive personal data of over 65,000 individuals.
GrayRobinson is a Florida-based full-service law firm founded in 1970. The firm provides legal services across areas such as real estate, healthcare, banking, litigation, and government affairs, serving businesses, government entities, and individuals through multiple offices in Florida and Washington, D.C.
In a data security incident notice filed with the Office of California Attorney General, GrayRobinson said that on March 24, 2025, it identified unauthorised access within its internal network. The law firm immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to contain the incident, secure the affected network and notified relevant law enforcement authorities about the same.
“Following the completion of our investigation, it was determined that some of our files may have been accessed or removed by the unauthorised individual(s) between March 5, 2025 and March 24, 2025,” GrayRobinson said.
The compromised data included names, dates of birth, Social Security Numbers, driver’s license numbers, state/government IDs, financial account information, medical information, and health insurance information. In a filing with the Maine state regulator, GrayRobinson said it has identified at least 65,113 individuals who were impacted by the incident.
“Upon learning of this issue, we immediately secured our network, reported the incident to law enforcement, and commenced a thorough investigation. As part of our investigation, we have been working very closely with external cybersecurity professionals experienced in handling these types of incidents,” the law firm added.
While GrayRobinson found no evidence of the compromised information being misused, it advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered complimentary identity protection and credit monitoring services through Experian IdentityWorks to all affected individuals.
At the time of publishing, no known hacker group claimed responsibility for the cyber attack on GrayRobinson. The law firm also did not share details on who was behind the attack, how much data was compromised, or whether it had received a ransom demand.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543