WilmerHale Reportedly Paid the Hackers $18 Million. Its Clients' Settlement Is $0 — and the Only Deadline That Exists Dies October 31.
One of America's most prominent law firms is the latest name in the Luna Moth extortion wave, and the search interest arrived before the facts did. There is no settlement, no claims administrator and no payout. What does exist: an official notification letter admitting a staffer was tricked into handing over data, a class action filed in Washington D.C., an unconfirmed insurance-press report of an eight-figure ransom — and an Experian enrollment code that stops working October 31, 2026.
By Settlement Insight Data Desk ·
What actually happened — in the firm's own words
Start with the primary source, because almost nothing written about this incident quotes it. WilmerHale's notification letter, dated July 15, 2026 and filed with the Washington State Attorney General, describes the incident in one sentence:
“On May 8, 2026, one of our personnel mistakenly provided information to an unauthorized third party who misrepresented their identity.”
Read that carefully, because it is not the sentence data-breach letters usually contain. Nobody hacked WilmerHale. No server was breached, no vendor was compromised, no file-transfer tool had a zero-day. A person at the firm was deceived by someone pretending to be someone else, and handed the data over. The letter is explicit on this point: the investigation “determined that this was an isolated incident, and that the third party did not directly access our systems.”
What went out the door: “The personal information involved in this incident was obtained through the course of providing certain legal services and may have included your name and Social Security Number.” That last phrase deserves emphasis too — this is data the firm held because people were its clients or connected to its legal work, not employee HR records.
The firm added, as these letters always do, that it is “not aware of any further disclosure or misuse of the information” — and its enclosure characterizes the exposed data as “unlikely to lead to healthcare, insurance, or financial fraud.” A name plus a Social Security Number is, for what it is worth, the exact pair used to open credit accounts, which is presumably why the same letter offers two years of credit monitoring.
The $18 million number — what it is and what it is not
The reason searches for this breach spiked in mid-August is almost certainly a single story. On August 7, 2026, the insurance trade publication The Insurer reported, citing its own sources, that WilmerHale paid at least $18 million in a ransom or suppression payment to the extortion group Luna Moth (also tracked as Silent Ransom Group) — and that CNA paid out a full $10 million primary layer on the firm's cyber insurance program.
Treat that number with precision. It is reported, not confirmed. WilmerHale has not confirmed paying anything; the firm did not respond to multiple outlets' requests for comment on the payment. No court document states it. We repeat it here because it is the fact driving the news cycle, with its sourcing attached — not because it has been verified.
What gives the report its plausibility is the pattern around it. Luna Moth has spent 2026 working through the top of the American legal industry: reporting across the trade press describes Goodwin Procter paying roughly $10 million, Weil Gotshal paying a reported $18–20 million in May, Mayer Brown having data leaked, and Jones Day reportedly refusing a $13 million demand. The FBI has said the group has targeted US law firms since spring 2023, using callback phishing and IT-helpdesk impersonation — someone calls or emails, convincingly plays a role, and talks an employee into granting access. Which is precisely the mechanism WilmerHale's own letter describes.
One more detail from the coverage, consistent with a payment but not proof of one: as of mid-August, WilmerHale's data has not appeared on any leak site.
Is there a settlement? No — here is the actual legal posture
If you searched some version of “WilmerHale data breach settlement,” here is the honest answer as of August 19, 2026: there is no settlement, no settlement fund, no claims administrator, no claim form and no payout. Anyone offering to “file your WilmerHale claim” today is at best collecting your contact information for a law firm's client list.
What exists is one lawsuit at its very beginning: Perry v. Wilmer Cutler Pickering Hale & Dorr LLP, filed July 14, 2026 in the U.S. District Court for the District of Columbia, case No. 1:26-cv-02470. The named plaintiff, a Las Vegas man who says he was a firm client, alleges negligence and breach of contract on behalf of thousands of affected people. The firm has not answered; no class has been certified; no ruling of any kind has issued.
Around that single case sits the usual first wave: at least four plaintiffs' firms announced “investigations” into the breach within days of the notification letters going out. An investigation is an advertisement. It creates no rights, no deadline and no money — it is how class counsel find named plaintiffs.
For calibration on timing: data-breach class actions that do settle typically take one to three years to reach a claims process. If this case follows the pattern, a real claim form — if one ever exists — is a 2027 or 2028 event. Nothing about the reported ransom changes that; a payment to extortionists is not an admission of liability to clients, and plaintiffs will have to prove their case or negotiate one.
The only deadline that exists right now: October 31
While the litigation is theoretical, one date in this incident is concrete, verified, and closer than it looks. The notification letter offers “complimentary access to Experian IdentityWorks for 24 months,” including credit monitoring across all three bureaus and $1 million of identity-theft insurance. And then, in bold on the letter itself:
“Ensure that you enroll by October 31, 2026 by 11:59 pm UTC (Your code will not work after this date.)”
Enrollment happens at experianidworks.com/1Bcredit and requires the personal activation code printed on your letter — there is no self-service path for people who lost it, though the letter says Experian's care team can verify eligibility using an engagement number. If your letter is in a mail pile from mid-July, that pile is currently worth something; the code inside it expires in ten weeks.
Note the asymmetry, because it repeats in every breach we cover: the free-protection deadline always arrives years before any settlement money does. People who wait to “see what the lawsuit pays” routinely let the monitoring window close first — and enrolling in the monitoring costs you nothing in the litigation. Signing up for Experian does not waive your right to be a class member, ever, in any breach case. The letter itself encourages enrollment while the class action proceeds in parallel.
How many people — the number nobody has published
WilmerHale has not stated a total. What exists is a patchwork of state regulatory filings, and they are worth listing precisely because they are so incomplete:
- Washington: 692 residents — the one figure we verified directly, from the Washington AG's breach database, which also lists the data types as name, Social Security Number and student ID number.
- South Carolina: 14,496 and Texas: 6,436 — per aggregator summaries of those states' AG filings, which we could not independently confirm.
- Smaller reported counts in Massachusetts (42), New Hampshire (35) and Vermont (11).
Sum the known states and you get roughly 21,700 people — a floor, not a total, since most states publish nothing. For a firm whose client base is corporations, funds and their executives, the interesting fact is less the count than the composition: this is a list of people connected to the legal matters of one of the country's most powerful firms.
A closing note on California: several secondary sources claim a July filing with the California AG, but two searches of California's public breach database returned no WilmerHale entry as of August 19. That is the kind of small discrepancy that follows this incident everywhere — which is exactly why everything in this article above the reported-versus-verified line is quoted from the firm's own letter, and everything below it is labeled.
The Data Behind This Story
- What happened
- May 8, 2026 — a staffer “mistakenly provided information to an unauthorized third party who misrepresented their identity” (official letter). Social engineering, not a systems hack.
- Data exposed
- Name and Social Security Number, obtained “through the course of providing certain legal services”; WA filing adds student ID numbers
- Settlement
- None. No fund, no administrator, no claim form. Any site claiming otherwise is not legitimate.
- Lawsuit
- Perry v. Wilmer Cutler Pickering Hale & Dorr LLP, No. 1:26-cv-02470 (D.D.C.), filed July 14, 2026 — negligence and breach of contract; no class certified, no ruling
- Reported ransom
- “At least $18 million” to Luna Moth, with CNA paying a $10M primary insurance layer — The Insurer, Aug 7, 2026. NOT confirmed by WilmerHale.
- The wider wave
- Luna Moth reportedly extracted $46M+ from Big Law since May: Goodwin (~$10M), Weil ($18–20M), Mayer Brown (leaked), Jones Day (refused $13M demand) — per trade-press reporting
- DEADLINE
- October 31, 2026, 11:59 pm UTC — Experian IdentityWorks enrollment; “Your code will not work after this date”
- Free protection
- 24 months Experian IdentityWorks + $1M identity-theft insurance — enroll at experianidworks.com/1Bcredit with the code from your letter
- Notification letters
- Dated July 15, 2026, sent via Return Mail Processing, Claysburg, PA
- People affected
- No official total. Verified: 692 (WA AG). Reported from state filings: 14,496 SC + 6,436 TX + smaller states ≈ 21,700 known — a floor, not a total
- Source: WilmerHale notification letter, dated July 15, 2026, filed with the Washington State Attorney General (agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41816.pdf) — retrieved and read in full August 19, 2026. Verbatim source of: “On May 8, 2026, one of our personnel mistakenly provided information to an unauthorized third party who misrepresented their identity”; “determined that this was an isolated incident, and that the third party did not directly access our systems”; “may have included your name and Social Security Number”; “not aware of any further disclosure or misuse”; the 24-month Experian IdentityWorks offer with $1,000,000 identity-theft insurance; and the enrollment deadline: “Ensure that you enroll by October 31, 2026 by 11:59 pm UTC (Your code will not work after this date.)” with enrollment at experianidworks.com/1Bcredit.
- Source: Washington State Attorney General data-breach notification database (atg.wa.gov/data-breach-notifications) — WilmerHale entry: date of breach 05/08/2026, date reported 07/15/2026, 692 Washingtonians affected, data types name / Social Security Number / student ID number.
- Source: The Insurer, “Exclusive: WilmerHale paid at least $18mn ransom to Luna Moth as CNA covered”, August 7, 2026 — source of the reported $18M+ payment, the CNA $10M primary layer and the Aon-brokered program. Paywalled; quoted via search index. WilmerHale did not respond to requests for comment and has not confirmed any payment. This figure is reported, not verified.
- Source: Bloomberg Law, “WilmerHale sued over client personal information data breach” (July 2026), and Cyber Security Incident Database entry d8e7bd3a — source of Perry v. Wilmer Cutler Pickering Hale & Dorr LLP, No. 1:26-cv-02470 (D.D.C.), filed July 14, 2026, named plaintiff Jason Perry of Las Vegas, claims of negligence and breach of contract.
- Source: Trade and industry coverage of the Luna Moth / Silent Ransom Group campaign against US law firms (The Insurer; nonbillable.co.uk, Aug 10, 2026; DataBreaches.net), including reported payments by Goodwin Procter (~$10M) and Weil Gotshal ($18–20M), the leaked Mayer Brown data, Jones Day's reported refusal of a $13M demand, and the FBI's description of the group's callback-phishing and IT-helpdesk impersonation methods since spring 2023. All figures in this paragraph are media-reported, not confirmed by the firms.
- Source: State-count figures for South Carolina (14,496), Texas (6,436), Massachusetts (42), New Hampshire (35) and Vermont (11) come from aggregator summaries of state AG filings (claimdepot.com) and could not be independently confirmed against those states' portals; they are labeled as reported. Two searches of the California AG's public breach database on August 19, 2026 found no WilmerHale entry, despite secondary claims of a California filing.
- Source: Verified absence: no settlement website, claims administrator or claim form exists for this incident as of August 19, 2026. openclassactions.com states: “No payout is guaranteed, and this investigation has not yet resulted in a settlement.” At least four plaintiffs' firms (Migliaccio & Rathod, Cole & Van Note, Dapeer, databreachattorney.net) are running client-solicitation “investigations” — these create no claims process.
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.