Hamill & Kaplan Waited Nearly 11 Months to Disclose a Breach That Exposed Client Social Security and Bank Account Numbers
A hacker was inside a tax and accounting firm’s network for a full day in September 2025. Clients whose Social Security numbers, government ID numbers, and bank account information were on file didn’t find out until August 2026, and even the Secret Service got involved.
Hamill & Kaplan, LLP, a tax and accounting firm based in Westlake Village, California, discovered on September 19, 2025 that an unauthorized user had gained access to its computer network earlier that same day. The firm’s investigation determined that the intruder accessed files containing client personal information. Notice letters to affected individuals are dated August 3, 2026, nearly eleven months after the firm learned of the intrusion.
A Tax Firm Breach Brings the IRS and the Secret Service Into It
Hamill & Kaplan’s notice states the firm reported the incident to the FBI, the IRS, the California Franchise Tax Board, and the U.S. Secret Service. That combination of agencies points to the specific danger here: this wasn’t a retailer losing email addresses, it was a firm holding the Social Security numbers, bank account information, and tax records that make fraudulent tax filings and government-benefits fraud possible. The firm’s own letter tells clients to report any suspicious IRS notices back to Hamill & Kaplan, and says the firm will do the same if it sees suspicious activity connected to a client’s tax return, an acknowledgment that tax-related identity theft is the primary concern.
What Information Was Exposed?
Per Hamill & Kaplan’s own notice letter, the information accessed included:
- Full Name
- Social Security Number
- Other Government Identification Numbers
- Bank Account Information
- Other Sensitive Information Provided to the Firm
How Many People Are Affected?
Hamill & Kaplan has not disclosed a specific number of affected individuals. The firm’s notice appears on the California Attorney General’s published breach notice list, and under California law, only breaches affecting more than 500 California residents are required to be posted there, meaning at least 500 Californians were notified.
What Is Hamill & Kaplan Offering?
Unlike most data breach notices, Hamill & Kaplan is not providing a prepaid credit monitoring service with an activation code. Instead, the firm’s letter directs recipients to contact Experian, Equifax, or TransUnion directly to obtain credit monitoring themselves, and separately recommends that affected individuals request an Identity Protection PIN from the IRS to help prevent fraudulent tax filings in their name.
Your Information Is at Risk
A Social Security number combined with a government ID number and bank account information is enough to file a fraudulent tax return, open new credit in someone’s name, or attempt to redirect a tax refund. The nearly eleven-month gap between discovery and notice gave any attacker a long head start. If you’re a current or former client of Hamill & Kaplan, watch for IRS notices about a return you didn’t file, unexpected credit inquiries, or unfamiliar bank activity, and consider requesting an IRS Identity Protection PIN even if you haven’t seen suspicious activity yet.
Do You Have Legal Options?
Accounting and tax firms that collect Social Security numbers, bank account information, and government ID numbers have a legal duty to secure that data and to notify clients without unreasonable delay.
Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you received a notice letter from Hamill & Kaplan.
FAQ
Who is affected by the Hamill & Kaplan data breach?
Current and former clients of Hamill & Kaplan, LLP whose personal information was in files an unauthorized user accessed on September 19, 2025. The firm has not disclosed a total number of affected individuals; California law confirms the incident affected at least 500 California residents.
What information was exposed?
Name, Social Security number, other government identification numbers, bank account information, and other sensitive information provided to the firm, per Hamill & Kaplan’s own notice.
Why did it take almost a year to be notified?
Hamill & Kaplan discovered the unauthorized access on September 19, 2025, but notice letters weren’t dated until August 3, 2026, nearly eleven months later. The firm’s letter does not explain the reason for the delay.
Is Hamill & Kaplan paying for credit monitoring?
No. The firm’s notice directs affected individuals to contact the credit bureaus directly on their own to obtain monitoring, rather than providing a prepaid service. The firm does recommend requesting an IRS Identity Protection PIN.
Do I have a legal claim?
Firms that collect Social Security numbers, bank account information, and government ID numbers have a legal duty to secure that data and to notify affected clients without unreasonable delay. If you received a notice from Hamill & Kaplan, contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 for a Free Case Review.