WilmerHale’s Data Breach Lawsuits Were Consolidated on August 19 Into a Single “In Re” Case. Six Weeks After the Letters Went Out, the Only Count Anyone Has Sworn To Is “Thousands to Tens of Thousands”
The searches exploded this month because the notification letters, dated July 15, 2026, are still working through the mail. Here is what the docket actually shows: two federal class actions in Washington D.C., a motion to consolidate filed August 12, an order on August 18, and a docket entry on August 19 that renamed the lead case. What the docket does not show — and no regulator we can reach will confirm — is how many people were affected. Still no settlement, no fund, no claim form.
By Settlement Insight Data Desk ·
What actually happened in the last two weeks
Searches for “wilmerhale data breach,” “letter from wilmerhale” and “wilmerhale data breach letter” rose roughly fourfold on our pages this week. That pattern — a spike in letter queries — is what a notification mailing looks like from the outside, and the letters in this case are dated July 15, 2026.
Meanwhile, the litigation quietly changed shape. The docket in the District of Columbia shows:
- July 14, 2026 — Jason Perry files the first class action complaint against Wilmer Cutler Pickering Hale & Dorr LLP, with a jury demand. Assigned the next day to Judge Emmet G. Sullivan.
- July 29, 2026 — Emily Egan files a second class action, No. 1:26-cv-02663, initially assigned to Judge Dabney L. Friedrich. Her complaint attaches her actual notice letter as Exhibit A.
- August 6, 2026 — Egan files a Notice of Related Case pointing to Perry’s case; the case is reassigned on August 7.
- August 12, 2026 — a motion to appoint counsel and consolidate cases is filed in the lead case.
- August 18, 2026 — an order issues.
- August 19, 2026 — the lead docket carries a “Consolidation” remark, and the second case records a “Create Case Association.”
The lead case is now captioned In re: Wilmer Cutler Pickering Hale & Dorr LLP, Data Breach Litigation, No. 1:26-cv-02470 (D.D.C.). A caption change from a named plaintiff to “In re” is the visible signature of consolidation.
One honest limit: the full text of the August 12 motion and the August 18 order sits behind PACER’s paywall, and no free copy has been contributed to the public archive. We can see what the entries are called and what the docket did; we are not going to characterise what the order says beyond that.
Nobody has publicly confirmed how many people were hit
This is the striking part. Six weeks after the letters were dated, there is still no authoritative public count.
The Egan complaint — a sworn federal filing — puts it this way: the breach resulted in the disclosure of the private information “of, upon information and belief, thousands to tens of thousands of individuals.” “Upon information and belief” is the phrase lawyers use when they are inferring rather than reporting. If the plaintiffs’ own lawyers had a firm number, it would be in the complaint.
The one figure we could verify against a primary government source is Washington State’s. The Washington Attorney General’s data breach register lists Wilmer Cutler Pickering Hale and Dorr LLP, breach start date 05/08/2026, 692 Washington residents affected, data involved: Name; Social Security Number; Student ID Number, reported 07/15/2026.
Aggregator sites currently report a nationwide total of roughly 95,000, assembled from six state filings with Texas said to account for about 80,500 of them. We could not verify that. The Texas Attorney General’s breach portal now sits behind a Salesforce login, and Maine’s viewer returned an authentication wall, so the two registries that would settle the question are no longer publicly readable. We are reporting the ~95,000 figure as unverified aggregator reporting, clearly labelled, precisely because we could not stand it up — and a number that cannot be checked should not be repeated as fact.
It is worth naming what that means: the public accounting of who was harmed in a breach at one of America’s most prominent law firms currently depends on which states still publish their registers.
What the letters said, and what the complaints allege
The official notification describes a social engineering incident, not a systems intrusion: a staffer “mistakenly provided information to an unauthorized third party who misrepresented their identity.” The incident date is May 8, 2026.
The Egan complaint sharpens the point that this framing is a choice. It argues that the phrase “misrepresented their identity” “minimizes that it was Defendant’s own conduct,” and faults the letter for not specifying what the firm did to verify the requester’s identity. Egan is described as a client of the firm who was required to hand over her name, contact information, date of birth, Social Security number and payment or financial account information as a condition of obtaining services. The complaint pleads negligence-type claims and asks for court-ordered security improvements alongside damages.
On remediation, the complaint says the firm offered 24 months of credit monitoring and argues that is inadequate for the exposure of a Social Security number, which — unlike a card number — cannot be reissued on request. The enrollment deadline printed in the notification letter is October 31, 2026. If you received a letter, enrolling is free and the code stops working after that date; there is no reason to wait for the litigation to resolve before using it.
An unconfirmed trade-press report in August put the firm’s ransom payment at “at least $18 million.” WilmerHale has not confirmed it and we are not treating it as established.
There is still no settlement — and that matters for a specific reason
To be unambiguous, because this is the question the search traffic is actually asking: there is no WilmerHale settlement. There is no settlement fund, no claims administrator, no claim form, no payout, and no deadline to claim money. Two class actions were filed weeks ago and have just been consolidated; no class has been certified and no court has ruled on the merits.
Cases like this take years, not weeks. The AMCA/LabCorp settlement finally approved this month covers a breach from 2018–2019 — seven years. That is the realistic clock.
The practical consequence: any website offering you a WilmerHale claim form, a payout estimate, or a “register now to join” flow is not connected to a court-authorized process, because none exists. During the gap between a notice campaign and an actual settlement, that gap is exactly what fraudulent and low-quality sites fill. If a real settlement is ever reached, it will have a court-authorized administrator and a named case, and the notice will come to you.
What is worth doing now is unrelated to the lawsuits: enrol in the offered monitoring before October 31, and consider a credit freeze at all three bureaus, which is free and does more against Social Security number misuse than monitoring does.
The Data Behind This Story
- Settlement
- NONE. No fund, no administrator, no claim form, no payout, no claim deadline.
- Lead case
- In re: Wilmer Cutler Pickering Hale & Dorr LLP, Data Breach Litigation, No. 1:26-cv-02470 (D.D.C.), Judge Emmet G. Sullivan — filed July 14, 2026 by Jason Perry
- Consolidation
- Motion to appoint counsel and consolidate filed August 12, 2026; order August 18; docket “Consolidation” remark August 19, 2026
- Second case
- Egan v. Wilmer Cutler Pickering Hale and Dorr LLP, No. 1:26-cv-02663 (D.D.C.), filed July 29, 2026; related-case notice August 6; associated August 19
- What happened
- May 8, 2026 — a staffer “mistakenly provided information to an unauthorized third party who misrepresented their identity.” Social engineering, not a systems hack.
- Notice letters
- Dated July 15, 2026, sent by U.S. mail
- How many affected
- UNCONFIRMED. Egan complaint: “upon information and belief, thousands to tens of thousands of individuals.”
- Only verified state count
- Washington AG register: 692 Washington residents; Name, Social Security Number, Student ID Number; breach start 05/08/2026, reported 07/15/2026
- Aggregator claim (unverified)
- ≈ 95,000 nationwide, Texas ≈ 80,500 — we could NOT verify: the Texas portal now requires a login and Maine’s viewer requires authentication
- Data exposed
- Name and Social Security Number (WA filing adds Student ID Number); Egan complaint also alleges date of birth and payment/financial account information
- Remediation offered
- 24 months of credit monitoring — enrollment deadline October 31, 2026 per the notification letter
- Reported ransom
- “At least $18 million” (trade press, August 2026) — NOT confirmed by WilmerHale
- Source: In re: Wilmer Cutler Pickering Hale & Dorr LLP, Data Breach Litigation, No. 1:26-cv-02470 (D.D.C.) — public docket via CourtListener, read August 23, 2026. Source of the July 14, 2026 Perry complaint and filing-fee receipt, the July 15 assignment to Judge Emmet G. Sullivan, the August 12 “Appoint Counsel AND Consolidate Cases” entry, the August 18 order entry, the August 19 “Remark - Consolidation” entry, the August 20 return of summons, and the current “In re” caption.
- Source: Egan v. Wilmer Cutler Pickering Hale and Dorr LLP, No. 1:26-cv-02663 (D.D.C.) — public docket via CourtListener plus the full text of the complaint (Document 1, filed 07/29/26, 44 pages) obtained from the RECAP archive and read directly. Source of the “upon information and belief, thousands to tens of thousands of individuals” allegation, the July 15, 2026 notice-letter date, the description of the plaintiff as a client, the categories of information alleged, the criticism of the “misrepresented their identity” wording, and the 24-months-of-credit-monitoring allegation. Also the August 6 Notice of Related Case, the August 7 reassignment and the August 19 “Create Case Association” entry.
- Source: Washington State Office of the Attorney General, data breach notification register — entry for “Wilmer Cutler Pickering Hale and Dorr LLP,” retrieved August 23, 2026: breach start 05/08/2026, 692 Washington residents, “Name; Social Security Number; Student ID Number,” reported 07/15/2026.
- Source: Texas Attorney General breach portal (oagtx.force.com) and the Maine Attorney General breach viewer, both attempted August 23, 2026: the Texas portal redirected to a Salesforce login and the Maine viewer returned “Authentication Required,” which is why the widely-circulated ≈ 95,000 nationwide figure and the ≈ 80,500 Texas figure are reported here as unverified aggregator claims rather than as fact.
- Source: The October 31, 2026 enrollment deadline and the “at least $18 million” ransom report were verified and sourced in our August 19, 2026 article on this breach; the ransom figure originates in insurance trade press and has not been confirmed by the firm.
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.