← All Articles

Addison v. Greenberg Traurig Alleges Law Firm Left 256,654 Records Unencrypted

Data Breach Exposed Sensitive Personal Information

A proposed class action filed in the United States District Court for the Southern District of New York alleges that Greenberg Traurig, P.A. and Greenberg Traurig, LLP (collectively, "Greenberg Traurig") failed to implement basic cybersecurity measures, allowing hackers to exfiltrate 1.18 GiB of unencrypted files containing the private information of over 256,654 individuals. The complaint, filed September 9, 2026, alleges that the exposed data included names, Social Security numbers, addresses, dates of birth, employment records, telephone numbers, email addresses, and financial information. The complaint further alleges that Defendants required this Private Information as a prerequisite for services (Compl. ¶58).

The plaintiffs, Bianca C. Addison, Jamaal Abraham, Kenneth Adams, and Christine Matthews, seek to represent a nationwide class of individuals whose private information was compromised in the breach. The complaint alleges that Greenberg Traurig, which markets itself as a "leader in data protection law" and employs attorneys who have authored "industry-recognized treatises on data privacy and security," disregarded industry standards and ethical obligations by storing sensitive data without encryption and failing to notify affected individuals. "Defendants disregarded the rights of Plaintiffs and Class Members by intentionally, willfully, recklessly, and/or negligently failing to implement reasonable measures to safeguard Private Information," the complaint states (Compl. ¶6).

The complaint also asserts that Plaintiffs were unaware Defendants possessed their Private Information at the time of the breach (Compl. ¶63, ¶93). For example, Plaintiff Addison alleges she was unaware Greenberg Traurig had her Private Information when the breach occurred (Compl. ¶63). Similarly, Plaintiff Matthews alleges she was unaware of Defendants' possession of her Private Information at the time of the breach (Compl. ¶93).

Unencrypted Files Posted on Dark Web, Plaintiffs Allege

The complaint alleges that the Silent Ransomware Group claimed responsibility for the data breach, during which hackers accessed and exfiltrated 1.18 GiB of confidential files. These files, which included plaintiffs' private information, were allegedly posted on the Dark Web, making them accessible to criminals. "Hackers have posted the unencrypted information, allowing other criminals to access the unredacted Private Information," the complaint states (Compl. ¶30).

The exposed data allegedly includes names, Social Security numbers (--***), addresses, dates of birth, employment records, telephone numbers, email addresses, and financial information. The complaint asserts that the breach has placed plaintiffs and class members at a heightened and imminent risk of fraud and identity theft for years to come. "Plaintiffs and Class Members now suffer from a heightened and imminent risk of fraud and identity theft for years to come," the complaint alleges (Compl. ¶7). The complaint further details that stolen Private Information trades on the black market for years and is posted on dark web sites (Compl. ¶103). Each record of stolen personally identifiable information (PII) or protected health information (PHI) can be worth up to $2,000.00 on the criminal black market (Compl. ¶102).

Cybercriminals are alleged to create "Fullz" packages—complete dossiers of stolen PII—which significantly increase the potential for misuse (Compl. ¶105-106). The complaint cites the FBI's Internet Crime Complaint Center (IC3) Report, which states that losses to individuals and business victims from internet-enabled crimes totaled $12.5 billion in 2023 (Compl. ¶108).

Plaintiff Addison, for example, alleges that her private information was posted on a publicly accessible database, exfiltrated by cybercriminals, and likely sold on the dark web. "This information has inherent value that Plaintiff was deprived of when her Private Information was placed on a publicly accessible database, exfiltrated by cybercriminals, and... placed for sale on the dark web," the complaint states (Compl. ¶65). Addison further alleges that she faces an imminent risk of fraud, identity theft, and misuse of her private information, causing her stress, fear, and anxiety. The complaint alleges that Defendants' failures caused monetary losses, lost time, anxiety, and emotional distress for Plaintiffs and Class Members (Compl. ¶101).

Failure to Comply with Industry Standards and Ethical Obligations

The complaint alleges that Greenberg Traurig failed to comply with multiple industry standards and guidelines, as well as federal data security recommendations. The firm is accused of disregarding the rights of plaintiffs and class members by intentionally, willfully, recklessly, or negligently failing to implement reasonable measures to safeguard private information. "Defendants failed to take appropriate measures to protect Plaintiffs’ and the Class Members’ Private Information," the complaint asserts (Compl. ¶139).

The complaint alleges that Greenberg Traurig failed to meet minimum standards of the NIST Cybersecurity Framework and CIS Critical Security Controls (Compl. Count 8). The firm is further accused of violating New York Rules of Professional Conduct Rule 1.6 and New York City Bar Formal Opinion 2024-3 by failing to notify affected individuals of the data breach. "Defendants failed to notify any Class Members of the Data Breach, violating ethical obligations," the complaint alleges (Compl. ¶49). The complaint also highlights that Defendants failed to notify current clients of compromised Private Information, as required by their ethical obligations (Compl. ¶47).

The plaintiffs assert that Greenberg Traurig's failures have left their Private Information unencrypted and vulnerable to ongoing unauthorized access. "The continued and certainly increased risk to their Private Information, which: (a) remains unencrypted and available for unauthorized third parties to access and abuse," the complaint states (Compl. ¶158).

Plaintiffs Seek Class Certification, Injunctive Relief, and Damages

The complaint seeks certification of a nationwide class consisting of approximately 256,654 individuals whose private information was accessed and compromised in the data breach. The plaintiffs allege that common questions of law and fact exist, including whether Greenberg Traurig unlawfully used, maintained, lost, or disclosed private information and whether it failed to implement reasonable security procedures. The amount in controversy exceeds $5,000,000, exclusive of interest and costs.

The plaintiffs assert counts of negligence, negligence per se under Section 5 of the Federal Trade Commission Act, unjust enrichment, breach of fiduciary duty, and breach of implied contract. The complaint alleges that Greenberg Traurig breached its duty of care by failing to implement reasonable security measures, leading to the theft of private information and resulting damages. "Defendants breached their duty to exercise reasonable care in safeguarding and protecting Plaintiffs’ and Class Members’ Private Information," the complaint states (Compl. ¶140).

The plaintiffs seek a range of remedies, including compensatory and punitive damages, lifetime credit monitoring and identity theft protection services, and injunctive relief to secure remaining data. The complaint requests that the court order Greenberg Traurig to implement and maintain a comprehensive Information Security Program, engage independent third-party security auditors for periodic testing, and prohibit the firm from maintaining Private Information on cloud-based databases until safeguards are implemented (Compl. ¶43). Additional requested measures include data segmentation with firewalls and access controls, regular database scanning and securing checks, monitoring of ingress and egress of all network traffic, annual information security training for employees, and the implementation of a threat management program (Compl. ¶43-44).

The complaint also seeks disgorgement of profits derived from Greenberg Traurig's alleged cost-cutting on security measures. "Defendants instead calculated to avoid its data security obligations at the expense of Plaintiffs and Class Members by utilizing cheaper, ineffective security measures," the complaint alleges (Compl. ¶165). Plaintiffs request that the court mandate notification of each Class Member about the Data Breach, purchase lifetime credit monitoring and identity theft protection services for each Class Member, and enjoin Defendants from further deceptive practices or untrue statements about the Data Breach (Compl. ¶45).

The allegations described here are taken from the filing and remain unproven; no responsive pleading is reflected in the source document.

David Brunk is a civil litigation attorney. He can be reached at david@newmanbrunk.com.

From the Complaint Public Court Record

1 UNITED STATES DISTRICT COURT SOUTHERN DISTRICT OF NEW YORK BIANCA C. ADDISON, JAMAAL ABRAHAM, KENNETH ADAMS, AND CHRISTINE MATTHEWS, individually and on behalf of all others similarly situated, Plaintiffs, v. GREENBERG TRAURIG, P.A. AND GREENBERG TRAURIG, LLP, Defendants. Case No. CLASS ACTION COMPLAINT PROPOSED CLASS ACTION Plaintiffs Bianca C. Addison, Jamaal Abraham, Kenneth Adams, and Christine Matthews, individually and on behalf of the Class defined below of similarly situated persons (“Plaintiffs and Class Members”), allege the following against Defendants, Greenberg Traurig, P.A. and Greenberg Traurig, LLP (“Defendants”). The following allegations are based on Plaintiffs’ knowledge, investigations by Plaintiffs’ counsel, facts of public record, and information and belief: NATURE OF THE ACTION 1. Plaintiffs seek to hold Defendants responsible for the injuries that Defendants inflicted on Plaintiffs and over 256,654 others due to Defendants’ egregiously inadequate data security, which resulted in the private information of Plaintiffs and those similarly situated to be exposed to unauthorized third parties (the “Data Breach”). 2. Defendants, headquartered in New York, NY, are a law firm that provides legal services for clients throughout the United States and Internationally. 1 One of Defendants’ areas of focus is Data Privacy and Cybersecurity, Defendants hold themselves out to be “leaders in data 1 Greenberg Traurig, Our Firm, https://www.gtlaw.com/en/our-firm (last accessed Sep. 4, 2026).

2 protection law” and includes “attorneys who have authored several industry-recognized treatises on data privacy and security”. 2 3. The data that Defendants exposed to the public is unique and highly sensitive. For one, the exposed data included personal identifying information (“PII”) like first name or first initial and last name along with one or more of the following: Social Security number, address, da

Questions about this topic: david@newmanbrunk.com

Practice areas