Skip to main content
Jump to a category page

Berkeley Research Group, a global consulting firm that works with law firms on litigation and bankruptcy matters, discovered a data breach in March 2025. Notice letters didn’t start going out until late August 2026 — roughly a year and a half later.

Berkeley Research Group, LLC (“BRG”), a global consulting firm headquartered in Emeryville, California, has notified individuals of a data breach. According to BRG’s own notice letter, the firm detected suspicious network activity on Sunday, March 2, 2025, and determined that an unauthorized actor had access to its systems from the evening of Friday, February 28, 2025, through March 2, 2025, and copied certain information during that window. BRG reported the breach to the California and Vermont Attorneys General on August 31, 2026, and to the Texas Attorney General on September 1, 2026 — approximately eighteen months after the incident was first detected.

Source: Berkeley Research Group, LLC’s own Notice of Data Breach letter; California, Vermont, and Texas Attorney General data-breach filings (reported 08/31/2026-09/01/2026, breach date 03/02/2025).

Why the Delay Matters

BRG’s letter does not explain why notice took roughly eighteen months from detection. BRG states it cooperated with federal law enforcement throughout its investigation and response, which can sometimes justify a delay in notifying the public — but an eighteen-month gap between detecting an intrusion and notifying the people affected is unusually long, and BRG has not publicly detailed the reason for it.

Sensitive Litigation-Support Records May Be Involved

BRG is a consulting firm that provides advisory and expert-witness services to clients and law firms, and it holds data in connection with those legal engagements. The U.S. Department of Justice has separately notified attorneys in a number of Catholic diocesan bankruptcy proceedings that this breach may have involved information belonging to clergy sexual abuse survivors whose claims BRG was helping to administer. If you are a survivor whose claim was handled through a diocesan bankruptcy process involving BRG, or a client of BRG for any other kind of legal or consulting engagement, your information may be part of this breach.

Source: U.S. Department of Justice notification to bankruptcy counsel, reported by DataBreaches.Net.

What Information Was Exposed?

BRG’s own notice letter does not itemize specific data categories in the sample version filed with regulators. According to independent reporting on the breach, the information involved may include:

  • Names, addresses, and dates of birth
  • Social Security numbers and tax identification numbers
  • Passport numbers, driver’s license numbers, or other government IDs
  • Financial and bank account information
  • Payment card numbers
  • Medical information and health insurance information

BRG has not itemized this list in its own publicly posted notice letter; it is drawn from independent reporting on the breach, and the specific categories that apply to you will be listed in your individual notice letter.

How Many People Are Affected?

BRG’s regulatory filings confirm 92,290 affected Texas residents and 1,314 affected Vermont residents. BRG also filed with the California Attorney General the same day, though that filing does not itemize a state-specific count. BRG has not disclosed a national total, but given the size of the confirmed state figures, the number of people affected nationwide is likely well into the hundreds of thousands.

What Is BRG Offering Affected Individuals?

BRG is offering twenty-four months of complimentary identity monitoring through Kroll, including credit monitoring, fraud consultation, and identity theft restoration services. Affected individuals can enroll at enroll.krollmonitoring.com using the membership number included in their notice letter, or call 1-866-291-2114, Monday through Friday, 9 a.m. to 6:30 p.m. Eastern Time.

Your Information Is at Risk

If the reported categories are accurate for you, the combination of Social Security numbers, financial account information, and payment card numbers creates a serious risk of identity theft and financial fraud, and medical or health insurance information adds the risk of medical identity theft. For anyone whose information reached BRG through a legal proceeding, including a sensitive matter like a bankruptcy claim, there is also a real privacy interest in records connected to that proceeding being exposed. Affected individuals should enroll in the monitoring BRG is offering and watch financial accounts and credit reports closely.

Do You Have Legal Options?

Companies that collect and store sensitive personal, financial, and legal-proceeding information have a legal duty to secure that data and to notify affected individuals without unreasonable delay.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you received a notice letter from Berkeley Research Group.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.

FAQ

Who is affected by the Berkeley Research Group data breach?

Anyone whose information BRG held in connection with a client engagement, including litigation-support, expert-witness, and bankruptcy-related work. BRG’s filings confirm 92,290 affected Texas residents and 1,314 affected Vermont residents; a national total has not been disclosed but is likely much larger.

What information was exposed?

BRG’s own posted notice letter does not itemize categories. Independent reporting on the breach describes names, addresses, dates of birth, Social Security numbers, tax ID numbers, passport and driver’s license numbers, financial and bank account information, payment card numbers, and medical and health insurance information as potentially involved. Check your individual notice letter for the categories that apply to you.

Why did it take BRG so long to notify people?

BRG detected the intrusion on March 2, 2025, but did not begin sending notice letters until late August 2026 — roughly eighteen months later. BRG has not publicly explained the reason for that gap, beyond noting it cooperated with federal law enforcement during its investigation.

I was involved in a diocesan bankruptcy case. Does this affect me?

Possibly. The U.S. Department of Justice has notified attorneys in a number of Catholic diocesan bankruptcy proceedings that this breach may involve information about clergy sexual abuse survivors whose claims BRG was helping administer. If you’re unsure whether your information was involved, contact us and we can help you figure out next steps.

Has a lawsuit been filed against BRG over this?

Multiple law firms have opened investigations into this breach, and litigation may already be underway. Emery | Reddy is conducting its own investigation and gathering information from affected individuals.

Do I have a legal claim?

Companies that collect and store sensitive personal, financial, and legal-proceeding information have a legal duty to secure that data and to notify affected individuals without unreasonable delay. If you received a notice letter from Berkeley Research Group, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now