The Berg Lilly P.C. Data Breach: Incident Facts and Free Case Review
Berg Lilly P.C. operates as a specialized legal practice handling complex litigation, corporate counseling, and sensitive client advisory services. Because of the nature of modern legal practice, law firms function as central repositories for an immense volume of highly confidential data. This includes deeply personal client records, corporate trade secrets, financial statements, proprietary litigation strategies, and comprehensive personally identifiable information (PII) belonging to individuals involved in legal proceedings. To effectively advocate for their clients and manage multifaceted legal matters, Berg Lilly P.C. routinely collects, processes, and stores sensitive documentation that demands the highest standards of digital security.
Received a Berg Lilly P.C. notification letter? Find out in minutes if you qualify for compensation.
Free case review- State
- Indiana
- Breach date
- May 20, 2026
- Reported
- August 28, 2026
What may have been exposed
- Full Name
- Social Security Number
- Date of Birth
- Financial Account Number
- Tax Return Information
- Confidential Legal Documents
- Home Address
- Phone Number
In 2026, Berg Lilly P.C. formally reported a significant security incident to the Indiana Attorney General, alerting clients and regulatory authorities that unauthorized actors had gained access to its network infrastructure. While investigations into legal sector cyberattacks frequently point toward sophisticated phishing campaigns, unauthorized entry into internal document management systems, or vulnerabilities within third-party vendor platforms, a breach of this magnitude typically indicates a critical breakdown in perimeter defense and network monitoring. For a law firm, such an intrusion allows malicious actors to dwell undetected within systems, siphoning off gigabytes of confidential files before the organization realizes its defenses have been compromised.
The exposure resulting from the Berg Lilly P.C. incident involves categories of data that carry severe and long-lasting risks for affected individuals. Compromised files frequently contain full names, Social Security numbers, dates of birth, financial account details, sensitive correspondence, and confidential legal documents. When Social Security numbers and financial records are exposed, victims face an immediate and elevated threat of identity theft, fraudulent credit card applications, and unauthorized bank withdrawals. Furthermore, the leakage of confidential legal files and private personal correspondence exposes victims to targeted phishing scams, extortion risks, and severe privacy violations that can impact both personal well-being and professional standing.
As a custodian of sensitive personal and corporate data, Berg Lilly P.C. was legally obligated to implement robust administrative, technical, and physical safeguards to secure its digital environment. Under Indiana data protection statutes and broader common law principles governing the handling of confidential information, entities holding PII must maintain reasonable security procedures appropriate to the nature of the data. The occurrence of a successful network intrusion and subsequent data exfiltration strongly suggests that the firm may have failed to meet these legal standards—potentially omitting necessary protocols such as multi-factor authentication, end-to-end encryption, routine vulnerability assessments, and proactive employee cybersecurity training.
For individuals who have received an official data breach notification letter from Berg Lilly P.C., this correspondence serves as formal acknowledgement that your private information was compromised due to inadequate security measures. Legally, the receipt of this notice establishes the concrete injury and standing necessary to participate in a class action lawsuit aimed at holding the firm accountable. Affected parties do not need to wait until financial fraud occurs to seek legal recourse. Our firm investigates these matters on a contingency fee basis, meaning you pay nothing out of pocket and owe no legal fees unless we successfully recover compensation on your behalf.
Received the Berg Lilly P.C. notification letter? The Berg Lilly P.C. case file tracks this filing.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Guard against tax fraud
File your tax return as early as possible and consider requesting an IRS Identity Protection PIN so no one can file a fraudulent return in your name.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Indiana Attorney General filing
Related data breach cases
- Teamsters Local 17
- Bank
- American Motorcyclist Association
- Deer Management Co. LLC dba Bessemer Venture Partners
- MEBS Global Reach
- McKenzie Creative Brands
- Midvale Indemnity and American Family Connect Insurance Company
- Nishiyamato Academy
- 9World Acceptance Corporation
- Chicago Psychoanalytic Institute
- Poppins Payroll Company
- Baltimore Medical System Inc
- Pavillon International Inc
- 7The Association of the Bar of the City of New York