GrayRobinson, P.A., a law firm, has notified individuals that it detected unauthorized access to its network on or about March 24, 2025. After securing its systems, reporting the incident to law enforcement, and working with outside cybersecurity investigators, GrayRobinson determined that an unauthorized party may have accessed or removed certain files between March 5, 2025 and March 24, 2025. It wasn’t until April 13, 2026, after a thorough review of the affected data, that the firm confirmed the impacted files may have contained personal information belonging to the people it is now notifying. This points to a case of hacking or system intrusion, and GrayRobinson says it has no evidence at this time that any exposed information has actually been used for fraud or identity theft.
The notice is being sent to individuals whose personal information was contained in the files the firm believes were accessed or removed during the intrusion window. GrayRobinson has not stated how many people in total were affected, so if you received a letter, you are among the specific group the firm identified through its review.
What information was exposed?
- Full name
The version of this letter we reviewed had a portion of the sentence describing the exposed data cut off after “your full name and,” so we can’t confirm from the text what other data types were listed for your specific notice. If your letter names additional information — such as a Social Security number, driver’s license number, or financial account details — treat those categories as exposed and follow the fuller precautions below. GrayRobinson is offering complimentary Experian IdentityWorksSM credit monitoring and identity restoration services as a precaution; enrollment is available at https://www.experianidworks.com/3bcredit, though the specific activation code, deadline, and membership length were not legible in the copy of the letter we reviewed, so check your personal letter for those details.
What should you do now?
- Enroll in the complimentary Experian IdentityWorks credit monitoring offered by GrayRobinson as soon as you locate your activation code and deadline in your letter.
- Review your letter carefully for any additional data types listed beyond your name, since that determines how seriously you should treat this incident.
- Place a free one-year fraud alert with one of the three major credit bureaus (Equifax, Experian, or TransUnion) — once one bureau is notified, they’ll alert the other two.
- Consider placing a security freeze on your credit files with Equifax, Experian, and TransUnion if you want the strongest protection against new accounts being opened in your name.
- Pull your free credit reports at annualcreditreport.com and check for accounts or inquiries you don’t recognize.
- Watch your bank and credit card statements closely for unfamiliar charges over the coming months.
- Consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, especially since it’s unclear from the available letter text whether more sensitive data was involved.
- If you notice suspicious activity, file a report with local law enforcement and the FTC at ftc.gov/idtheft.
If you have questions, GrayRobinson, P.A. can be reached by mail at 301 E. Pine Street, Suite 1400, Orlando, Florida 32801.