Blank Rome LLP, a national law firm with offices across more than a dozen U.S. cities, disclosed a data breach that exposed clients’ Social Security numbers and financial account numbers. The firm reported that the breach occurred on May 21, 2026, and filed a formal notification with the California Department of Justice. The exposure of these specific identifiers carries direct risk for affected individuals, because Social Security and financial account numbers are the primary tools identity thieves use to open fraudulent credit lines or file false tax returns.
How the Blank Rome breach creates risk across state lines
The California filing, cataloged as state breach record, confirms the date of the incident and the types of data compromised. California requires companies to notify the state attorney general whenever a breach affects its residents, regardless of how many people are involved. That low threshold means California filings often surface before notices in states with higher reporting triggers.
Texas, by contrast, requires a company to report a breach only when it affects 250 or more Texas residents, and the firm then has a 30-day window to file. A law firm like Blank Rome, which serves corporate and individual clients nationwide, could easily trip reporting thresholds in some states while falling below them in others. The result is a patchwork: clients in one state may receive notice weeks before clients elsewhere learn their data was exposed, if those clients receive notice at all.
This gap matters because the window between a breach and the moment a victim learns about it is when the most damage typically occurs. Fraudulent accounts can be opened, tax refunds redirected, and credit scores damaged before a person even knows to freeze their credit file. For clients of a law firm, whose files may also contain litigation histories, business records, or family financial details, the downstream consequences of identity theft can be particularly disruptive and long-lasting.
State databases confirm the breach but leave key questions open
Delaware’s public breach dataset, updated through July 8, 2026, tracks entity names, breach date ranges, report dates, and resident counts for every incident reported to the state. The dataset allows independent verification of when a company filed and how many Delaware residents were affected. Cross-referencing this database with the California filing establishes a timeline that public records can support.
The Delaware Attorney General also maintains a separate portal that explains how incidents are logged into the state notification database. Together, these resources outline the minimum information companies must provide, including the nature of the breach and the categories of data involved. However, they do not require firms to publish detailed narratives about how attackers gained access or what specific safeguards failed.
The total number of affected individuals across all states has not been disclosed in the available regulatory filings. The California notice confirms the categories of data lost, but the full consumer notice PDF has not been released in the public index beyond its metadata. Blank Rome LLP has not issued a public statement detailing what remediation steps it is offering, such as credit monitoring or identity theft protection services, leaving clients to infer their options from generic guidance in state-level materials.
Without a firm-wide count, it is difficult to assess whether the breach meets reporting thresholds in every state where Blank Rome operates. The firm maintains offices in cities including New York, Philadelphia, Houston, and Washington, D.C., meaning its client base spans dozens of jurisdictions with different notification rules. Whether filings have been submitted in all relevant states is not yet clear from available records, and because some states publish less detail than California or Delaware, the public picture of the incident remains incomplete.
What affected clients should do before more details emerge
The exposure of Social Security numbers and financial account numbers puts affected individuals at sustained risk. Unlike a stolen password, a Social Security number cannot be changed. Anyone who has worked with Blank Rome and suspects their data was compromised should assume that criminals may attempt to use that information months or even years after the initial breach.
Clients who receive a notification letter should first read it carefully for instructions on any complimentary credit monitoring or identity theft protection the firm may be offering. Even if such services are not mentioned, individuals can take immediate defensive steps. Placing a fraud alert with one of the major credit bureaus requires that bureau to notify the others, making it harder for new accounts to be opened without additional verification. For stronger protection, a credit freeze can block most new credit checks entirely until the consumer lifts it.
Because financial account numbers were exposed, affected people should review bank and credit card statements closely and set up automated alerts for withdrawals, transfers, or purchases over a modest threshold. If any unfamiliar transactions appear, they should be reported to the financial institution at once, as federal law often limits liability when fraud is reported quickly.
Tax-related identity theft is another concern. Clients should watch for notices from the IRS or state tax authorities about returns they did not file, and consider filing their taxes as early as feasible in future years so that fraudulent returns are less likely to be accepted first. Keeping copies of the breach notice and any correspondence from Blank Rome may help if they need to dispute debts or prove that their information was exposed.
Until Blank Rome or regulators provide a fuller accounting of the breach, clients have to rely on these standard precautions to reduce their risk. The incident underscores how uneven state reporting rules can leave individuals with incomplete information, even when the data at stake includes some of the most sensitive identifiers in the U.S. financial system.
Free for readers: The free Retirement Shield newsletter sends plain-English help keeping more of your money in retirement — the scams to dodge, the benefits you’re owed, and what’s changing with Social Security and Medicare, a couple times a week. Get the free newsletter.



