DataBreachCaseFile.com
MonitoringMontana AG filing · December 15, 2025

TorHoerman Law Data Breach Exposes Client Private Information

TorHoerman Law, LLC, a prominent law firm, reported a data breach in December 2025 that compromised sensitive client information. The exposed data includes financial and medical records, along with various personal identifiers, affecting individuals who entrusted the firm with their private details.

State
Montana
Breach date
May 27, 2025
Reported
December 15, 2025

What may have been exposed

  • Full Name
  • Social Security Number
  • Date of Birth
  • Home Address
  • Phone Number
  • Medical Records and Treatment History
  • Financial Account and Settlement Details
  • Driver's License Number
  • Email Address

TorHoerman Law, LLC, a legal firm operating in Montana, disclosed a data security incident on December 15, 2025. This breach originated from an event that occurred on May 27, 2025. The firm, known for its work in complex litigation, is monitoring the situation following the compromise of client data.

The reported exposure includes a wide range of sensitive personal data. Affected individuals may have had their Full Name, Social Security Number, Date of Birth, Home Address, Phone Number, Driver's License Number, and Email Address compromised. Additionally, Medical Records and Treatment History, along with Financial Account and Settlement Details, were part of the exposed information.

Such an incident can carry significant risks for those affected. The exposure of identifiers like Social Security Numbers and Driver's License Numbers could lead to potential identity theft or financial fraud. Similarly, the compromise of Medical Records and Treatment History, combined with Financial Account and Settlement Details, raises privacy concerns and could be misused.

Individuals who receive a notification regarding this incident are advised to take immediate protective steps. It is recommended to monitor financial accounts and credit reports for any suspicious activity. Placing a fraud alert or security freeze on credit files can help prevent unauthorized access to new credit. Additionally, reviewing explanations of benefits from healthcare providers for unfamiliar services is a prudent measure.

Further safeguarding measures include changing passwords for online accounts, especially those linked to the compromised email address, and being vigilant against unsolicited communications. These might be phishing attempts using the exposed personal information to gain further access or commit fraud.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Replace exposed ID documents

    Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.

  • Secure your online accounts

    Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Montana Attorney General filing

Related data breach cases