Compliance · · 4 min read
Four California breach filings point to single-account exposure
Notices from three professional-services firms describe documents accessed after attackers compromised individual accounts, while a fourth filing remains unreadable.
California’s breach notification list received filings from four professional-services firms over October 1 and 2, 2026. The notices from Aldrich Services, Greenberg Traurig, Sheppard, Mullin, Richter & Hampton, and Fragomen, Del Rey, Bernsen & Loewy arrived within 48 hours of one another.
Three of the filings can be examined in readable form. Each describes an incident centred on one employee account rather than a software flaw, outside supplier or ransomware attack. In the incidents described by Sheppard Mullin, Fragomen and Aldrich, access to a single identity gave an unauthorised person a route to files or email.
Severity Daily’s report says the clustering does not establish that the breaches were connected. The incidents occurred on different dates, and the available notices identify no shared vendor or attacker. The concentration of filings at the start of October may simply reflect when the firms completed their reviews and submitted notifications.
What the three readable notices say
Sheppard Mullin’s notice, dated October 2 and issued from its Los Angeles office, concerns a social-engineering attack against one attorney. The firm says the incident led to confidential documents being disclosed to an unknown third party. It learned of the event on September 1, the day after it occurred, then hired external forensic specialists and contacted law enforcement.
The firm had not finished determining exactly what information was contained in the affected files or which individuals were represented in them. It offered affected people two years of credit monitoring and identity-theft protection through TransUnion, administered by Cyberscout. The package includes up to $1 million in identity-theft insurance, and enrolment is available until December 31, 2026.
Fragomen’s notice describes an earlier event involving remote access to one user account. The firm concluded that the access formed part of a social-engineering campaign and that the intruder copied some files. California’s listing places the unauthorised activity on May 4 and 5, 2026. The notice does not identify the second category in the data description because that field is redacted. Fragomen is offering 24 months of Experian IdentityWorks monitoring.
Aldrich Services, an accounting and advisory firm, reported suspicious activity involving an employee email account. The account was accessed by an unknown person from August 22 to August 23, 2026. Aldrich says it secured the account, investigated, and notified law enforcement and relevant regulators. Its sample notice does not identify the method used to gain entry, and the duration of its monitoring service is not visible in the available filing.
Greenberg Traurig’s filing was posted on October 1 and gives August 26 as the breach date. Its notice is connected to the same incident as filings in Vermont and California previously covered by Severity Daily on September 11, 2026. The sample PDF could not be converted into readable text, so the filing provides no additional details for this account.
Why the timing matters
California requires organisations to send the attorney general a sample notification when a single breach affects more than 500 California residents. The threshold confirms that each of these incidents involved at least that many Californians, but the filings do not state the actual number of people affected. The state’s public list also does not provide a total.
The dates show different intervals between the apparent access and the notices. Sheppard Mullin’s letter was dated 32 days after the end of its incident window. Aldrich’s followed 39 days after the account activity ended. Fragomen’s notice came 150 days after the listed May access.
Those intervals cannot, by themselves, establish when each firm discovered its breach. California requires notification at the most expedient time possible and without unreasonable delay, rather than setting one fixed number of days for every case. Fragomen’s letter does not explain whether the firm identified the intrusion in May and spent months investigating, or discovered it later. That distinction is important because notification timing depends partly on when an organisation knows what happened and who may be affected.
The broader exposure from one account
The filings illustrate why account compromise can be especially consequential at professional-services firms. A single lawyer’s or adviser’s credentials may open access to material belonging to numerous clients, cases or transactions. The affected people may have no direct relationship with the firm and may not know that it stores their personal documents.
The two-year monitoring offers from Sheppard Mullin and Fragomen also reflect the uncertainty that can follow a document-focused breach. When investigators are still identifying the files involved, the eventual data categories may be broader than the initial notification can specify.
For clients of the firms, the practical issue is not merely whether an account was compromised. It is whether a particular matter was within that account’s reach and whether the review has reached that material. Sheppard Mullin’s investigation was still under way when its notice was issued, so the absence of a further contact does not necessarily resolve that question.
The incidents also point to controls beyond conventional vulnerability management. Organisations can reduce the consequences of social engineering by limiting how much one authenticated user can access, requiring renewed authentication for large exports, monitoring unusual download volumes and reviewing weekend activity. In Aldrich’s case, the recorded access occurred on a Saturday and Sunday, making out-of-hours activity a potentially useful signal for investigators and security teams.