▼
Allegations Only · No Settlement Yet
This article describes class action complaints. The statements below are unproven
allegations. Blank Rome LLP has not been found liable, there is no certified class, and
there is nothing to claim at this time. This page is general information, not legal advice.
Blank Rome LLP — a national law firm with 16 offices — is facing proposed class actions over a
data breach that allegedly exposed sensitive personal information belonging to its clients. The lead
case is Delapaz v. Blank Rome LLP, No. 2:26-cv-04655-JFM, filed July 6, 2026 in the U.S.
District Court for the Eastern District of Pennsylvania, where the firm is headquartered. A second,
nearly identical suit — Santana v. Blank Rome — was filed the same day in the same court.
The complaints are brought on behalf of clients whose personal information was allegedly accessed by
an unauthorized third party during the incident. They allege the firm failed to implement reasonable,
industry-standard cybersecurity safeguards to protect the sensitive information entrusted to it, and
that it waited more than a month to notify affected people. None of the claims has been proven, and
no court has ruled on the merits.
Status
Complaint Filed · No Settlement
two suits filed July 6, 2026 in the Eastern District of Pennsylvania
People Affected
57,554
names, SSNs & other sensitive data, per the firm's breach notice
Can I Claim?
No — nothing to claim yet
no certified class, no settlement, no claim form
According to the firm's breach notice and a filing with the California Attorney General, the incident
occurred on May 21, 2026, when an unauthorized third party caused files containing clients' personal
information to be uploaded to an external Google Drive account. Reporting on the incident describes it
as a social-engineering attack — the attacker allegedly posed as a member of the firm's IT team to
trick an employee into moving the data. Blank Rome began mailing notification letters on or about
June 26, 2026, more than a month after the incident.
The firm reported that the breach affected 57,554 current, former, and prospective clients. The
complaints allege the exposed information could include names, Social Security numbers, dates of
birth, taxpayer identification numbers, driver's license and state ID numbers, passport and other
government-issued ID numbers, financial account and payment card information, and medical and health
insurance information — though the specific fields exposed vary by individual. No hacking group has
been publicly confirmed as responsible, and any attribution you may see reported remains unconfirmed.
The firm has offered affected people complimentary credit monitoring. The complaints argue that
several months of monitoring does not address the long-term risk tied to data — such as Social
Security numbers — that cannot be changed.
The lawsuits assert that Blank Rome was negligent in securing the personal information in its
possession and bring related claims for breach of implied contract, unjust enrichment, breach of
fiduciary duty, and breach of confidence, along with violations of several California statutes — the
Unfair Competition Law, the California Consumer Privacy Act, and the California Customer Records Act.
The complaints allege the firm collected and stored sensitive client data and therefore owed a duty
to protect it with reasonable security measures, and that the breach was a foreseeable consequence of
failing to do so, particularly given the wave of cyberattacks targeting large law firms in recent
years.
The plaintiffs seek class certification, monetary damages, and injunctive relief that would require
court-ordered improvements to the firm's data security practices, plus attorneys' fees. Because the
cases were just filed, Blank Rome has not yet responded in court, and no schedule has been set.
The proposed class covers people in the United States whose information was compromised in the breach
— described in the complaints as the firm's current, former, and prospective clients — including
everyone who received a data breach notice. The exact class definition will be tested as the cases
proceed, and anyone who received a notification letter from Blank Rome dated on or around June 26,
2026 is likely within the group the complaints describe. If you received a notice, keep it: if the
litigation ever settles, documentation of class membership is typically required or helpful.
Law firms are attractive targets for attackers because they hold concentrated volumes of sensitive
client information, and Blank Rome is not the first major firm to face breach litigation. We cover a
similar recently filed case against another large firm in our
WilmerHale data breach class action
article and the
Pillsbury Winthrop data breach class action,
and an open settlement over a litigation-support breach in our
Compex Legal Services data breach settlement
coverage.
There is nothing to file at this stage — no settlement and no claim form exist. If you received a
breach notice from Blank Rome, standard post-breach precautions apply: enroll in any credit
monitoring the firm offers, consider placing a free fraud alert or security freeze on your credit
files with the three credit bureaus, and monitor financial accounts for unfamiliar activity. Because
Social Security numbers are alleged to be involved, a credit freeze is the strongest available
protection against new-account identity theft.
You can follow other active breach cases on our
data breach settlements and investigations tracker.
OpenClassActions.com is a consumer news site, not a law firm, and does not provide legal advice or
process claims.
What is the Blank Rome data breach lawsuit about?
A proposed class action, Delapaz v. Blank Rome LLP, filed July 6, 2026 in the U.S. District Court for the Eastern District of Pennsylvania, alleges the law firm failed to adequately protect sensitive personal information that an unauthorized third party accessed during a May 2026 data breach. A second, nearly identical suit (Santana v. Blank Rome) was filed the same day. These are unproven allegations; Blank Rome has not been found liable and there is no certified class.
What happened in the Blank Rome data breach?
According to the firm's breach notice and a filing with the California Attorney General, an incident on May 21, 2026 caused files containing clients' personal information to be uploaded to an external Google Drive account controlled by an unauthorized third party. News reports on the incident describe it as a social-engineering attack in which someone posing as the firm's IT team tricked an employee. Blank Rome began mailing notification letters on or about June 26, 2026.
How many people were affected by the Blank Rome breach?
Blank Rome reported that the breach affected 57,554 current, former, and prospective clients, according to its breach notice and its filing with the California Attorney General. The complaint alleges the exposed data included names, Social Security numbers, driver's license and passport numbers, financial account and payment card information, and medical and health insurance information.
Is there a Blank Rome settlement or claim form yet?
No. The cases are at the complaint stage. There is no certified class, no settlement, and no claim form. Nothing can be claimed at this time. If the litigation later settles, a court-approved notice and official settlement website would explain who qualifies and how to file.
What should I do if I received a Blank Rome breach notice?
Keep the notice letter — if a settlement is ever reached, it may be needed to document class membership. Consider standard post-breach precautions: enroll in any credit monitoring the firm offers, place a free fraud alert or credit freeze with the three credit bureaus, and watch financial statements for unfamiliar activity. Because Social Security numbers are alleged to be involved, a credit freeze is the strongest protection against new-account identity theft.
• Delapaz v. Blank Rome LLP, No. 2:26-cv-04655-JFM (E.D. Pa.) — Class Action Complaint, filed July 6, 2026
• Bloomberg Law, "Blank Rome Sued Over Breach Exposing Data of Over 57,000 People" —
Bloomberg Law
• Law360, "Blank Rome Sued Over Breach Allegedly Affecting 57K People" —
Law360
• The Legal Intelligencer (Law.com), "Blank Rome Sued Twice Over May Cyber Breach" —
The Legal Intelligencer
• Above the Law, "Blank Rome Hit With Two Class Actions After Data Breach Exposes 57,000 Clients" —
Above the Law
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
For more class actions keep scrolling below.
Status
Complaint filed — no settlement, no certified class
Case Title
Delapaz v. Blank Rome LLP (one of two related suits)
Case Number
2:26-cv-04655-JFM
Court
U.S. District Court, Eastern District of Pennsylvania
Date Filed
July 6, 2026
People Affected
57,554
Data Types
Names · SSNs · driver's licenses · passports · financial, payment card & medical info