Fried, Frank, Harris and Shriver & Jacobson LLP: Fried Frank Hit With Goldman Investment Data Breach Suit (1)

Fried, Frank, Harris and Shriver & Jacobson LLP: Fried Frank Hit With Goldman Investment Data Breach Suit (1)

Fried Frank Law Firm Faces Class Action Over Data Breach Exposing Goldman Sachs Investors’ Sensitive Information

A class action lawsuit filed on December 24, 2025, in the U.S. District Court for the Southern District of New York alleges that international law firm Fried, Frank, Harris, Shriver & Jacobson LLP failed to protect the personal data of investors in a Goldman Sachs private equity fund. The complaint, brought by plaintiff Andrew Sacks, claims the firm’s security lapse exposed sensitive information, including Social Security numbers, addresses, and banking details, without notifying affected individuals or offering credit monitoring.

Goldman Sachs Asset Management LP confirmed the breach on December 19, notifying account holders of the incident at Fried Frank. However, Sacks—an investor in the Petershill Private Equity Seeding II Offshore Fund—stated he was never directly informed by the law firm, only learning of the breach through Goldman. He argues that had he known of Fried Frank’s inadequate security, he would not have entrusted his data to the firm.

Fried Frank acknowledged the incident in a statement, noting it took immediate action to contain the breach, engaged external cybersecurity experts, and reported the matter to law enforcement. The firm maintained that its client services remained uninterrupted.

The lawsuit seeks damages and a court order requiring Fried Frank to cover at least 10 years of credit monitoring for affected individuals, citing the long-term risks of identity theft. Claims include negligence, breach of implied contract, breach of fiduciary duty, and unjust enrichment. The case, Sacks v. Fried, Frank, Harris, Shriver & Jacobson LLP (No. 1:25-cv-10693), represents all individuals notified of the breach on or after December 19.

Source: https://news.bloomberglaw.com/litigation/fried-frank-firm-hit-with-goldman-investment-data-breach-suit

Fried Frank cybersecurity rating report: https://www.rankiteo.com/company/friedfrank

"id": "FRI1766606165",
"linkid": "friedfrank",
"type": "Breach",
"date": "12/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Account holders of Goldman '
                                              'Sachs Petershill Private Equity '
                                              'Seeding II Offshore Fund',
                        'industry': 'Legal Services',
                        'location': 'International',
                        'name': 'Fried, Frank, Harris, Shriver & Jacobson LLP',
                        'type': 'Law Firm'},
                       {'customers_affected': 'Investors in the Petershill '
                                              'Private Equity Seeding II '
                                              'Offshore Fund',
                        'industry': 'Financial Services',
                        'location': 'International',
                        'name': 'Goldman Sachs Asset Management LP',
                        'type': 'Asset Management'}],
 'customer_advisories': 'Notification sent by Goldman Sachs on December 19, '
                        '2024; no direct notification from Fried Frank.',
 'data_breach': {'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Addresses',
                                              'Social Security Numbers',
                                              'Banking Information']},
 'date_publicly_disclosed': '2024-12-19',
 'description': 'International law firm Fried, Frank, Harris, Shriver & '
                'Jacobson LLP allegedly failed to adequately safeguard '
                'sensitive personal information of account investments '
                'associated with a Goldman Sachs private equity fund. A class '
                'action lawsuit claims the firm did not notify affected '
                'account holders or offer credit monitoring services after a '
                'security incident.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'alleged negligence',
            'customer_complaints': 'Yes (class action lawsuit filed)',
            'data_compromised': 'Sensitive personal information including '
                                'addresses, social security numbers, and '
                                'banking information',
            'identity_theft_risk': 'High (exposure of SSNs and banking '
                                   'information)',
            'legal_liabilities': 'Class action lawsuit filed (negligence, '
                                 'breach of implied contract, breach of '
                                 'fiduciary duty, unjust enrichment)',
            'operational_impact': 'No disruption to client services reported',
            'payment_information_risk': 'High (banking information exposed)'},
 'investigation_status': 'Ongoing',
 'recommendations': 'Offer credit monitoring services to affected individuals, '
                    'improve communication strategies for breach '
                    'notifications, and enhance data security measures to '
                    'prevent future incidents.',
 'references': [{'source': 'Bloomberg Law'},
                {'date_accessed': '2024-12-24',
                 'source': 'Complaint filed in US District Court for the '
                           'Southern District of New York'}],
 'regulatory_compliance': {'legal_actions': 'Class action lawsuit filed (Sacks '
                                            'v. Fried, Frank, Harris, Shriver '
                                            '& Jacobson LLP)'},
 'response': {'communication_strategy': 'No direct notification to affected '
                                        'individuals; notification via Goldman '
                                        'Sachs',
              'containment_measures': 'Prompt action to contain the incident',
              'incident_response_plan_activated': 'Yes',
              'law_enforcement_notified': 'Yes',
              'third_party_assistance': 'Industry-leading, external data '
                                        'security experts'},
 'title': 'Fried Frank Data Security Incident and Alleged Failure to Safeguard '
          'Sensitive Information',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.