Did 282Cornick, Garber, & Sandler LLP have a data breach?
Answer
Yes. 282Cornick, Garber, & Sandler LLP reported a data breach to the Indiana Attorney General on April 2, 2026.
View the official filingWhat the filing says
- Reported to
- Indiana Attorney General
- Filing date
- April 2, 2026
- Breach date
- February 14, 2025
- People affected
- Not stated in the filing
Information involved
- Full Name
- Social Security Number
- Date of Birth
- Home Address
- Financial Account Details
- Tax Return Information
- Confidential Legal Correspondence
- Phone Number and Email Address
In plain terms
Cornick, Garber, & Sandler LLP operates as a prominent legal services firm, handling complex litigation, corporate governance, estate planning, intellectual property, and confidential client advisory matters. Because of the sensitive nature of the legal work they perform, the firm routinely collects, processes, and stores vast quantities of highly confidential information. This includes not only internal employee and operational records but also extensive proprietary business documents, financial statements, trade secrets, personally identifiable information (PII), and sensitive client records entrusted to the firm during active representation and litigation.
In 2026, Cornick, Garber, & Sandler LLP reported a significant data security incident to the Indiana Attorney General, triggering legal scrutiny and mandatory notifications. While the precise vector of the compromise—whether driven by sophisticated external ransomware, unauthorized third-party network access, or an infrastructure misconfiguration—remains under active review, security incidents impacting legal institutions typically involve unauthorized actors gaining entry to enterprise document management systems and legacy databases. Law firms are prime targets for cybercriminals precisely because they act as centralized repositories for high-value corporate and individual data.
The data compromised in the breach encompasses a dangerous cross-section of personal and professional identifiers. Depending on the scope of the affected systems, exposed records likely include full names, dates of birth, Social Security numbers, banking and trust account details, tax documents, and confidential correspondence detailing sensitive legal and financial disputes. When exposed, these categories of information create severe, multi-faceted risks for victims. Social Security numbers and personal identifiers lay the groundwork for long-term identity theft and fraudulent credit applications, while compromised financial and tax records expose individuals and corporate clients to immediate financial account takeovers and fraudulent wire transfers.
Under Indiana state data protection statutes, as well as common law duties of care and professional ethics obligations regarding client confidentiality, Cornick, Garber, & Sandler LLP had a strict legal responsibility to implement and maintain robust administrative, physical, and technical safeguards to secure this data. Professional service firms are expected to adhere to industry-standard data security frameworks, including end-to-end encryption, multi-factor authentication, regular vulnerability assessments, and strict access controls. The occurrence of a data breach of this magnitude strongly suggests potential failures in these foundational security protocols, raising serious questions about whether the firm adequately protected the sensitive information entrusted to its care.
Receiving an official data breach notification letter from Cornick, Garber, & Sandler LLP is a formal acknowledgment that your private information was compromised due to the firm's security failures. Legally, this notice establishes that your data was exposed, granting you standing to participate in a class action lawsuit aimed at holding the firm accountable. Importantly, victims do not need to wait until financial fraud has already occurred to seek legal recourse; the increased risk of future identity theft and the loss of privacy are recognized harms. Our firm evaluates these cases on a contingency fee basis, meaning you pay nothing out of pocket, and we only collect a fee if we successfully recover compensation on your behalf.
Commonly recommended next steps
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Guard against tax fraud
File your tax return as early as possible and consider requesting an IRS Identity Protection PIN so no one can file a fraudulent return in your name.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Secure your online accounts
Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Look up another company
Other breaches reported in Indiana
- Teamsters Local 17Yes — reportedIndiana
- BankYes — reportedIndiana
- PeoplesBankYes — reportedIndiana · October 8, 2026
- McKenzie Creative BrandsYes — reportedIndiana · September 30, 2026
- MEBS Global ReachYes — reportedIndiana · September 30, 2026
- Midvale Indemnity and American Family Connect Insurance CompanyYes — reportedIndiana · September 30, 2026
- American Motorcyclist AssociationYes — reportedIndiana · September 30, 2026
- Nishiyamato AcademyYes — reportedIndiana · September 30, 2026
- Deer Management Co. LLC dba Bessemer Venture PartnersYes — reportedIndiana · September 30, 2026
- 9World Acceptance CorporationYes — reportedIndiana · September 30, 2026
DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with 282Cornick, Garber, & Sandler LLP.