Blank Rome Data Breach Class Action Lawsuit (2026)
Data Breach · Lawsuit Filed

Blank Rome Data Breach Class Action: Law Firm Sued After 57,554 Clients' Data Was Uploaded to a Hacker's Google Drive

Published July 22, 2026

Blank Rome, one of the country's larger law firms, is facing proposed class actions after a May 2026 data breach the firm reported affected 57,554 people — clients' names, Social Security numbers, and other sensitive data allegedly uploaded to an outside Google Drive. The cases were just filed: there is no settlement and nothing to claim yet, but anyone who received a breach notice should keep it.

Blank Rome data breach class action lawsuit over a 2026 law firm cyberattack that exposed client names and Social Security numbers
Allegations Only · No Settlement Yet

This article describes class action complaints. The statements below are unproven allegations. Blank Rome LLP has not been found liable, there is no certified class, and there is nothing to claim at this time. This page is general information, not legal advice.

What Is the Blank Rome Data Breach Lawsuit About?

Blank Rome LLP — a national law firm with 16 offices — is facing proposed class actions over a data breach that allegedly exposed sensitive personal information belonging to its clients. The lead case is Delapaz v. Blank Rome LLP, No. 2:26-cv-04655-JFM, filed July 6, 2026 in the U.S. District Court for the Eastern District of Pennsylvania, where the firm is headquartered. A second, nearly identical suit — Santana v. Blank Rome — was filed the same day in the same court.

The complaints are brought on behalf of clients whose personal information was allegedly accessed by an unauthorized third party during the incident. They allege the firm failed to implement reasonable, industry-standard cybersecurity safeguards to protect the sensitive information entrusted to it, and that it waited more than a month to notify affected people. None of the claims has been proven, and no court has ruled on the merits.

Status Complaint Filed · No Settlement two suits filed July 6, 2026 in the Eastern District of Pennsylvania
People Affected 57,554 names, SSNs & other sensitive data, per the firm's breach notice
Can I Claim? No — nothing to claim yet no certified class, no settlement, no claim form

What Happened in the Blank Rome Data Breach?

According to the firm's breach notice and a filing with the California Attorney General, the incident occurred on May 21, 2026, when an unauthorized third party caused files containing clients' personal information to be uploaded to an external Google Drive account. Reporting on the incident describes it as a social-engineering attack — the attacker allegedly posed as a member of the firm's IT team to trick an employee into moving the data. Blank Rome began mailing notification letters on or about June 26, 2026, more than a month after the incident.

The firm reported that the breach affected 57,554 current, former, and prospective clients. The complaints allege the exposed information could include names, Social Security numbers, dates of birth, taxpayer identification numbers, driver's license and state ID numbers, passport and other government-issued ID numbers, financial account and payment card information, and medical and health insurance information — though the specific fields exposed vary by individual. No hacking group has been publicly confirmed as responsible, and any attribution you may see reported remains unconfirmed.

The firm has offered affected people complimentary credit monitoring. The complaints argue that several months of monitoring does not address the long-term risk tied to data — such as Social Security numbers — that cannot be changed.

What Do the Complaints Allege?

The lawsuits assert that Blank Rome was negligent in securing the personal information in its possession and bring related claims for breach of implied contract, unjust enrichment, breach of fiduciary duty, and breach of confidence, along with violations of several California statutes — the Unfair Competition Law, the California Consumer Privacy Act, and the California Customer Records Act. The complaints allege the firm collected and stored sensitive client data and therefore owed a duty to protect it with reasonable security measures, and that the breach was a foreseeable consequence of failing to do so, particularly given the wave of cyberattacks targeting large law firms in recent years.

The plaintiffs seek class certification, monetary damages, and injunctive relief that would require court-ordered improvements to the firm's data security practices, plus attorneys' fees. Because the cases were just filed, Blank Rome has not yet responded in court, and no schedule has been set.

Who Could Be Affected?

The proposed class covers people in the United States whose information was compromised in the breach — described in the complaints as the firm's current, former, and prospective clients — including everyone who received a data breach notice. The exact class definition will be tested as the cases proceed, and anyone who received a notification letter from Blank Rome dated on or around June 26, 2026 is likely within the group the complaints describe. If you received a notice, keep it: if the litigation ever settles, documentation of class membership is typically required or helpful.

Law firms are attractive targets for attackers because they hold concentrated volumes of sensitive client information, and Blank Rome is not the first major firm to face breach litigation. We cover a similar recently filed case against another large firm in our WilmerHale data breach class action article and the Pillsbury Winthrop data breach class action, and an open settlement over a litigation-support breach in our Compex Legal Services data breach settlement coverage.

What Should You Do Now?

There is nothing to file at this stage — no settlement and no claim form exist. If you received a breach notice from Blank Rome, standard post-breach precautions apply: enroll in any credit monitoring the firm offers, consider placing a free fraud alert or security freeze on your credit files with the three credit bureaus, and monitor financial accounts for unfamiliar activity. Because Social Security numbers are alleged to be involved, a credit freeze is the strongest available protection against new-account identity theft.

You can follow other active breach cases on our data breach settlements and investigations tracker. OpenClassActions.com is a consumer news site, not a law firm, and does not provide legal advice or process claims.

Frequently Asked Questions

What is the Blank Rome data breach lawsuit about?

A proposed class action, Delapaz v. Blank Rome LLP, filed July 6, 2026 in the U.S. District Court for the Eastern District of Pennsylvania, alleges the law firm failed to adequately protect sensitive personal information that an unauthorized third party accessed during a May 2026 data breach. A second, nearly identical suit (Santana v. Blank Rome) was filed the same day. These are unproven allegations; Blank Rome has not been found liable and there is no certified class.

What happened in the Blank Rome data breach?

According to the firm's breach notice and a filing with the California Attorney General, an incident on May 21, 2026 caused files containing clients' personal information to be uploaded to an external Google Drive account controlled by an unauthorized third party. News reports on the incident describe it as a social-engineering attack in which someone posing as the firm's IT team tricked an employee. Blank Rome began mailing notification letters on or about June 26, 2026.

How many people were affected by the Blank Rome breach?

Blank Rome reported that the breach affected 57,554 current, former, and prospective clients, according to its breach notice and its filing with the California Attorney General. The complaint alleges the exposed data included names, Social Security numbers, driver's license and passport numbers, financial account and payment card information, and medical and health insurance information.

Is there a Blank Rome settlement or claim form yet?

No. The cases are at the complaint stage. There is no certified class, no settlement, and no claim form. Nothing can be claimed at this time. If the litigation later settles, a court-approved notice and official settlement website would explain who qualifies and how to file.

What should I do if I received a Blank Rome breach notice?

Keep the notice letter — if a settlement is ever reached, it may be needed to document class membership. Consider standard post-breach precautions: enroll in any credit monitoring the firm offers, place a free fraud alert or credit freeze with the three credit bureaus, and watch financial statements for unfamiliar activity. Because Social Security numbers are alleged to be involved, a credit freeze is the strongest protection against new-account identity theft.

Sources

Delapaz v. Blank Rome LLP, No. 2:26-cv-04655-JFM (E.D. Pa.) — Class Action Complaint, filed July 6, 2026
• Bloomberg Law, "Blank Rome Sued Over Breach Exposing Data of Over 57,000 People" — Bloomberg Law
• Law360, "Blank Rome Sued Over Breach Allegedly Affecting 57K People" — Law360
• The Legal Intelligencer (Law.com), "Blank Rome Sued Twice Over May Cyber Breach" — The Legal Intelligencer
• Above the Law, "Blank Rome Hit With Two Class Actions After Data Breach Exposes 57,000 Clients" — Above the Law



For more class actions keep scrolling below.
Status Complaint filed — no settlement, no certified class
Case Title Delapaz v. Blank Rome LLP (one of two related suits)
Case Number 2:26-cv-04655-JFM
Court U.S. District Court, Eastern District of Pennsylvania
Date Filed July 6, 2026
People Affected 57,554
Data Types Names · SSNs · driver's licenses · passports · financial, payment card & medical info

Related Data Breach Lawsuits & Settlements