Greenberg Traurig Data Breach Notice (California OAG)
If you received a notice from Greenberg Traurig, here’s what the filing says was exposed, and what to do about it.
The international law firm filed a data breach notice with the California Attorney General on September 9, 2026 following unauthorized access and limited posting of documents containing SSNs to the dark web. The firm notified affected clients and stated core systems were not compromised.
The unauthorized posting of documents containing your Social Security number to the dark web means that a permanent identifier tied to your identity is now available to unknown parties. This exposure cannot be undone or reissued the way a credit card or password can.
Greenberg Traurig, an international law firm, filed notice with the California Attorney General on September 9, 2026, stating that an incident occurred on August 26, 2026. The filing lists social security numbers and personal information as exposed. The record does not state how many people were affected.
Social Security Numbers Retain Full Value Indefinitely
Unlike passwords or credit card numbers, a Social Security number cannot be changed at will. Once it appears on the dark web, it remains a usable key for identity theft, tax fraud, loan applications in your name, or government benefit claims for as long as it stays valuable to criminals. The filing confirms this category was included in the limited set of documents posted.
Personal information listed alongside the Social Security numbers increases the risk that someone can build a convincing profile to pass identity verification checks. No passwords were exposed in this incident.
What the Law Firm’s Notification Actually Tells You
The organization has stated it notified affected clients directly. For most people, that notification—usually sent by mail to the last known address—is the only reliable way to determine whether your records were among those involved. If you have not received such a letter, it is likely your information was not included. However, if you have moved since the incident date of August 26, 2026, you should contact Greenberg Traurig directly to confirm your status.
The filing does not disclose the exact initial access vector, whether the documents were encrypted at rest, or the full scope of any internal controls. Core systems were not compromised, according to the firm’s statement. The record itself establishes only the categories exposed and the filing date.
Why This Exposure Matters More Than Many Others
Because a Social Security number cannot be replaced, the risk does not expire. Criminals can hold this data for years and use it when an opportunity arises—such as filing a fraudulent tax return in early spring or opening accounts during a period when your attention is elsewhere. The combination of an SSN with additional personal information makes synthetic identity fraud or account takeover attempts easier to execute convincingly.
At the same time, the absence of credential exposure in the filing is meaningful. You do not need to treat this as a signal to change every password you own. The threat centers on identity theft rather than direct account compromise at the firm itself.
The Gap Between Incident and Notification
The incident occurred on August 26, 2026. The firm filed the notice with California authorities on September 9, 2026. That short interval means notification reached affected individuals relatively quickly after the unauthorized posting was identified. The record does not provide a discovery date separate from these two points, so no further timeline can be established from the filing.
What Remains Under Your Control
While the Social Security number itself cannot be altered, several practical steps can limit what criminals are able to do with it. These actions focus on monitoring, early detection, and reducing the downstream damage that often follows SSN exposure.
- Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This prevents new accounts from being opened in your name without your explicit permission and is one of the most effective responses to SSN exposure.
- Monitor your tax account with the IRS through their online portal and set up alerts for any unexpected filings or correspondence. Fraudulent tax returns are a common first use of stolen SSNs.
- Review Explanation of Benefits statements from health insurers carefully. Even though medical information is not listed in this filing, identity thieves sometimes use SSNs to access or create medical services in your name.
- Set up alerts on your bank and credit card accounts for any unusual activity. While the firm’s core systems were not compromised, the personal information now circulating can be used in phishing attempts that appear legitimate.
- Contact Greenberg Traurig directly if you have changed addresses since August 2026 or if you believe you should have received notification but have not. Only the organization can confirm whether your specific records were part of the limited documents posted.
The filing establishes that this was a contained event involving documents rather than a broad system compromise. That distinction matters. Your exposure is real if you were among those notified, but it is bounded. Focus on the permanent nature of the Social Security number and the monitoring steps that give you the best chance of catching misuse early.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Greenberg Traurig.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
149 Million Credential Mega-Exposure — January 2026
Security researchers discovered a publicly exposed 96 GB database with 149 million unique logins cov…
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
PayPal SSN Exposure Lasting Six Months — February 2026
A code change at PayPal allowed unauthorized access to Social Security Numbers and account details f…