DataBreachPayment.com
MonitoringIndianaFiled August 28, 2026

Berg Lilly P.C. data breach: you may be owed a payment

If a Berg Lilly P.C. letter arrived in your mailbox, here is what it means, why you received it, and the free steps you can take right now.

Why you received this letter

Berg Lilly P.C. operates as a specialized legal practice handling complex litigation, corporate counseling, and sensitive client advisory services. Because of the nature of modern legal practice, law firms function as central repositories for an immense volume of highly confidential data. This includes deeply personal client records, corporate trade secrets, financial statements, proprietary litigation strategies, and comprehensive personally identifiable information (PII) belonging to individuals involved in legal proceedings. To effectively advocate for their clients and manage multifaceted legal matters, Berg Lilly P.C. routinely collects, processes, and stores sensitive documentation that demands the highest standards of digital security. In 2026, Berg Lilly P.C. formally reported a significant security incident to the Indiana Attorney General, alerting clients and regulatory authorities that unauthorized actors had gained access to its network infrastructure. While investigations into legal sector cyberattacks frequently point toward sophisticated phishing campaigns, unauthorized entry into internal document management systems, or vulnerabilities within third-party vendor platforms, a breach of this magnitude typically indicates a critical breakdown in perimeter defense and network monitoring. For a law firm, such an intrusion allows malicious actors to dwell undetected within systems, siphoning off gigabytes of confidential files before the organization realizes its defenses have been compromised. The exposure resulting from the Berg Lilly P.C. incident involves categories of data that carry severe and long-lasting risks for affected individuals. Compromised files frequently contain full names, Social Security numbers, dates of birth, financial account details, sensitive correspondence, and confidential legal documents. When Social Security numbers and financial records are exposed, victims face an immediate and elevated threat of identity theft, fraudulent credit card applications, and unauthorized bank withdrawals. Furthermore, the leakage of confidential legal files and private personal correspondence exposes victims to targeted phishing scams, extortion risks, and severe privacy violations that can impact both personal well-being and professional standing. As a custodian of sensitive personal and corporate data, Berg Lilly P.C. was legally obligated to implement robust administrative, technical, and physical safeguards to secure its digital environment. Under Indiana data protection statutes and broader common law principles governing the handling of confidential information, entities holding PII must maintain reasonable security procedures appropriate to the nature of the data. The occurrence of a successful network intrusion and subsequent data exfiltration strongly suggests that the firm may have failed to meet these legal standards—potentially omitting necessary protocols such as multi-factor authentication, end-to-end encryption, routine vulnerability assessments, and proactive employee cybersecurity training. For individuals who have received an official data breach notification letter from Berg Lilly P.C., this correspondence serves as formal acknowledgement that your private information was compromised due to inadequate security measures. Legally, the receipt of this notice establishes the concrete injury and standing necessary to participate in a class action lawsuit aimed at holding the firm accountable. Affected parties do not need to wait until financial fraud occurs to seek legal recourse. Our firm investigates these matters on a contingency fee basis, meaning you pay nothing out of pocket and owe no legal fees unless we successfully recover compensation on your behalf.

Information the filing reports as involved

  • Full Name
  • Social Security Number
  • Date of Birth
  • Financial Account Number
  • Tax Return Information
  • Confidential Legal Documents
  • Home Address
  • Phone Number

What to do after the letter

  1. Confirm the notice is genuine

    A legitimate Berg Lilly P.C. notice references the specific incident reported to the Indiana Attorney General and describes which categories of your information were involved. Compare the letter against the public filing before acting on any links or phone numbers it contains.

  2. Keep the letter — it is your proof of connection

    The notification letter is the document that ties your personal information to this incident. Keep the original and photograph it. If you later request a case review, this letter is the strongest evidence that you were among the affected individuals.

  3. Protect your accounts and credit

    Depending on what was exposed, consider a free credit freeze with all three bureaus, new passwords for reused credentials, and monitoring of financial statements. These steps are free and do not require you to wait for anyone's permission.

  4. Find out whether you have a claim

    Whether the Berg Lilly P.C. breach gives you a legal claim depends on the facts. A free, no-obligation case review will tell you where you stand — there is no cost and no commitment to find out.

This page summarizes a data breach reported to the Indiana Attorney General for informational purposes and is attorney advertising. It does not create an attorney-client relationship. DataBreachPayment.com does not provide legal advice through this page.