Tarter Krinsky & Drogin LLP Data Breach Notice (Vermont Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Tarter Krinsky & Drogin LLP notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on June 05, 2026, and the notice lists social security numbers, financial account codes, credit and debit account info, health records among the information exposed.
The filing from Tarter Krinsky & Drogin LLP, reported to the Vermont Attorney General on June 05, 2026, states that information belonging to 34 people was exposed. The categories listed are Social Security Numbers, financial account codes, credit and debit account info, and health records.
A Social Security Number cannot be replaced
If your Social Security Number was among the records included in this incident, it remains permanently tied to your identity. Unlike a credit card or password, it cannot be reissued on request. This single number, when paired with a name and date of birth, allows criminals to open new accounts, file fraudulent tax returns, or apply for government benefits in your name. Those risks do not expire when the news cycle moves on.
The same filing lists health records. Medical information carries its own lifelong consequences: it can be used to commit insurance fraud, obtain prescription drugs illegally, or blackmail individuals who would prefer certain diagnoses stay private. Credit and debit account details add immediate financial exposure if the numbers remain valid.
What this exposure actually enables
With a Social Security Number and health records, identity thieves can build a convincing profile. They can request duplicate insurance cards, schedule procedures billed to your policy, or combine the data with publicly available information to answer security questions on financial accounts. Financial account codes increase the chance that existing accounts are targeted for takeover or that new lines of credit are opened without your knowledge.
No passwords were exposed in this incident. That is genuine good news. You do not need to change any password for Tarter Krinsky & Drogin LLP because none was compromised. The risk lies entirely in the non-credential data that cannot be rotated.
How to determine whether this filing concerns you
Tarter Krinsky & Drogin LLP is required to notify affected individuals directly, usually by mail. If you receive a letter from the firm, it will tell you exactly which categories of your information were included. Absence of a letter usually means your records were not part of the 34 affected. However, because the filing does not state when the incident occurred, anyone who has moved since their last interaction with the firm should contact Tarter Krinsky & Drogin LLP directly to confirm their status.
The permanent versus the manageable
Social Security Numbers and health records belong to the permanent category. You cannot delete them from the databases where they now potentially reside. Credit and debit account information sits in the manageable category: those numbers can be canceled and replaced. The distinction matters because your effort should focus on the things you can still control while accepting that the unchangeable pieces require ongoing vigilance.
Health records are especially sticky. Once exposed, they can reappear in unexpected places years later. A fraudulent claim filed against your insurance today can create problems when you need legitimate care next year. Monitoring Explanation of Benefits statements becomes essential, not optional.
Why the small number still matters
Only 34 Vermont residents are named in this filing. Small scale does not mean small risk for those affected. When a law firm holds sensitive client data, the combination of Social Security Numbers and health records is particularly valuable because it often ties directly to high-net-worth individuals or those with complex financial and medical histories. The 34 people on this list face above-average exposure precisely because of the type of organisation involved.
Concrete steps that address this specific exposure
- Place a fraud alert with the three major credit bureaus immediately. This forces lenders to verify your identity before opening new accounts and lasts for one year. It is the fastest way to block most new-account identity theft enabled by an exposed Social Security Number.
- Review every Explanation of Benefits statement from your health insurer. Look for claims you did not file or services you did not receive. Report discrepancies to your insurer at once; early detection limits damage from medical identity theft.
- Order and examine your credit reports from Equifax, Experian, and TransUnion. Dispute any unfamiliar accounts or inquiries. Because financial account codes were exposed, existing accounts should be monitored for unusual activity even if the cards themselves were not lost.
- Enroll in credit monitoring that alerts you to new inquiries or accounts opened in your name. The monitoring should specifically watch for tax-related fraud given the presence of Social Security Numbers.
- Contact Tarter Krinsky & Drogin LLP directly if you have not received a letter but believe you may have been a client during the relevant period. Ask for written confirmation of whether your records were included.
The exposure of these particular categories means the incident will require attention for years rather than months. Social Security Numbers retain value to criminals for decades. Health records do not lose their sensitivity over time. While you cannot undo what happened, you can limit what thieves manage to do with the information by acting on the pieces still under your control.
The filing itself contains no information about how the data was accessed or whether it was copied. Those details remain unknown. What is known is narrow but serious: 34 people had their Social Security Numbers, financial account information, and health records listed in a Vermont breach notification on June 05, 2026. For those individuals, the letter in the mail is the beginning of a new routine of monitoring and verification that did not exist before.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Tarter Krinsky & Drogin LLP.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…