Mogren, Glessner & Ahrens, P.S., a King County, Washington law firm, spotted a ransomware intrusion the day after it began — then took three months to contain it and notify anyone.
Mogren, Glessner & Ahrens, P.S., a Washington law firm practicing family law, divorce, probate, wills, criminal defense, personal injury, and adoption, reported a ransomware breach to the Washington Attorney General on September 3, 2026, confirming 1,379 affected Washington residents. According to the firm’s own reporting to Washington regulators, unauthorized access began June 9, 2026, and the firm became aware of it the very next day, June 10, 2026.
Source: Washington Attorney General data breach notification directory, submitted 09/03/2026 (Socrata record id 25379).
Fast Detection, Slow Everything Else
This case has an unusual shape. Washington’s own regulatory data shows the firm identified the intrusion in just one day — about as fast as detection gets. But containment took far longer: the access window is recorded as running through September 10, 2026, roughly 93 days of exposure. Notice to the Washington Attorney General wasn’t submitted until September 3, 2026 — 85 days after the firm first became aware something was wrong. Because detection wasn’t the problem here, the firm can’t point to a slow discovery process to explain the delay in getting the breach contained and disclosed.
Source: Washington Attorney General Socrata breach data (datestart 06/09/2026, dateaware 06/10/2026, dateend 09/10/2026, datesubmitted 09/03/2026, dayselapsedbeforenotification 85).
A Ransomware Group’s Claim
A group calling itself Pear has claimed responsibility for the attack, according to independent ransomware-tracking sources. Mogren, Glessner & Ahrens has not confirmed this claim in its own public filing, and Emery | Reddy is presenting it as unverified — the confirmed fact is the Washington regulatory filing itself, not the attacker’s own account.
Why a Law Firm Breach Is Different
Mogren, Glessner & Ahrens isn’t a retailer or a hospital — it’s a law firm, and the files it holds include client records connected to family law, probate, criminal defense, and adoption matters. That kind of information is often presumptively private and sensitive by its nature, independent of whether it includes a Social Security number or financial account data. A breach at a firm handling those practice areas raises privacy concerns that go beyond typical identity-theft exposure.
What Information Was Exposed?
The Washington filing does not itemize specific categories of exposed information. What’s confirmed is the number of Washington residents affected — 1,379 — and the ransomware classification of the attack. Anyone who has been a client of the firm should treat their file as potentially involved until more specific information becomes available.
Do You Have Legal Options?
Law firms that collect and store confidential client information have a legal duty to secure it and to notify affected individuals without unreasonable delay.
If you’re a current or former client of Mogren, Glessner & Ahrens, P.S., contact Emery | Reddy today for a Free Case Review.
FAQ
Who is affected by the Mogren, Glessner & Ahrens data breach?
The firm confirmed 1,379 affected Washington residents in its filing with the Washington Attorney General. As a Washington-based practice, this figure likely represents most or all of the affected population.
What information was exposed?
The Washington filing does not itemize specific categories of exposed information. Given the firm’s practice areas, client files may include family law, probate, criminal defense, and adoption records.
Has a hacking group claimed responsibility?
A group calling itself Pear has claimed responsibility according to independent ransomware-tracking sources. The firm has not confirmed this claim in its own public filing.
Why did it take so long to be notified if the firm caught the breach so fast?
The firm identified the intrusion within a day, but didn’t submit notice to Washington regulators until roughly 85 days later, and the access window stayed open for about 93 days. Fast detection didn’t translate into fast containment or fast notice.
Do I have a legal claim?
Law firms that collect and store confidential client information have a legal duty to secure it and to notify affected individuals without unreasonable delay. If you’re a current or former client of Mogren, Glessner & Ahrens, P.S., contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.