Knox McLaughlin Gornall & Sennett PC Data Breach Lawsuit Investigation
On October 7, 2025, Knox McLaughlin Gornall & Sennett PC (“KMG&S”) disclosed an email security incident that compromised sensitive client information, including Social Security and medical data. If you received a breach notification, you may be entitled to no-cost credit monitoring and potential legal remedies—take action below.
Speak with a data-breach lawyer or enroll in the complimentary protection services today.
Download Official Breach Notice (PDF)Key Facts at a Glance
- Date breach detected: May 14, 2025
- Unauthorized access occurred: May 19, 2025
- Public disclosure: October 7, 2025
- Type of attack: Unauthorized access to one employee email account
- Data exposed: Name, Social Security number, driver’s license number, health-insurance policy number, medical condition or treatment information
- Free services offered: 12-month single-bureau credit monitoring and proactive fraud assistance through Cyberscout
- States reporting: Maine Attorney General
What Happened
During routine security monitoring on May 14, 2025, KMG&S identified suspicious activity within a single employee’s email account. A cybersecurity firm was immediately engaged to investigate. The review confirmed that certain files in the mailbox were accessed or acquired without authorization on May 19, 2025.
The law firm describes the event as isolated and reports no evidence of misuse of the affected information to date. A comprehensive file review later revealed that personal details belonging to clients and other individuals were present in the compromised mailbox, prompting notification letters mailed on October 7, 2025.
Information Involved
KMG&S indicates that the following data elements may have been exposed:
- Name
- Social Security number
- Driver’s license number
- Health-insurance policy number
- Medical condition or treatment information
Company Response
According to the notice filed with the Maine Attorney General, KMG&S has:
- Engaged external cybersecurity specialists to investigate the incident.
- Implemented additional technical and administrative safeguards to reduce future risk.
- Offered affected individuals:
- Complimentary single-bureau credit monitoring, credit report and credit score alerts for 12 months (through TransUnion/Cyberscout).
- Proactive fraud assistance through Cyberscout.
- Provided a unique activation code and 90-day enrollment window for the free services.
Recommended Next Steps for Victims
- Enroll in the free credit-monitoring service by following instructions in your mailed letter.
- Review your credit reports and medical Explanation of Benefits for unfamiliar activity.
- Place a fraud alert or security freeze with the credit bureaus if you notice suspicious changes.
- Keep all breach-related correspondence; it may be needed for legal or insurance purposes.
- Consult a data-breach attorney to discuss compensation for any time or costs incurred.
Timeline of Events
- May 14, 2025 — Suspicious email activity detected.
- May 19, 2025 — Unauthorized access to mailbox confirmed.
- May – September 2025 — Forensic review and data analysis conducted.
- October 7, 2025 — Consumer notification letters and regulatory filing issued.
Company Overview
Knox McLaughlin Gornall & Sennett PC is a Pennsylvania-based law firm providing business, tax, and litigation services.
- Website: kmgslaw.com
- Headquarters: 120 West 10th Street, Erie, Pennsylvania, United States
- Year founded: 1958
- Industry: Legal Services
- Employee count: 40 +
- LinkedIn: Company Page
- Facebook: Firm Profile
Frequently Asked Questions
What happened in the Knox McLaughlin Gornall & Sennett PC data breach?
An unauthorized party accessed one employee’s email account on May 19, 2025, potentially viewing files containing personal and health information.
What personal data was exposed by Knox McLaughlin Gornall & Sennett PC?
The firm reports exposure of names, Social Security numbers, driver’s license numbers, health-insurance policy numbers, and medical condition or treatment details.
How do I activate my free credit monitoring?
Use the unique code provided in your mailed notice and enroll at the Cyberscout activation portal within 90 days of the letter date.
Have there been any reports of identity theft?
KMG&S states it has no evidence of misuse at this time, but impacted individuals should remain vigilant.
Do I qualify for a Knox McLaughlin Gornall & Sennett PC lawsuit?
If you received a notice, you may be eligible to file a claim for potential damages. Consult a qualified data-breach attorney to evaluate your options.
How long do I have to take legal action?
Statutes of limitation vary by state. Contact a lawyer promptly to preserve your rights.
What is Knox McLaughlin Gornall & Sennett PC doing to prevent future incidents?
The firm says it has implemented additional security measures and continues to monitor its systems.