In February 2023, Kerber, Eck & Braeckel LLP experienced a data breach exposing highly sensitive personal and financial information of approximately 103,645 individuals. The compromised data included names, Social Security numbers, addresses, dates of birth, driver’s license numbers, financial account details, medical treatment records, and health insurance information. The breach led to a $1.4 million class-action settlement, offering affected individuals credit monitoring, reimbursement for economic losses (up to $10,000), and a pro rata cash payment (~$50). The lawsuit alleged negligence in safeguarding data, though the firm denied wrongdoing. The incident highlights severe risks of identity theft, financial fraud, and long-term reputational harm due to the exposure of comprehensive personal and medical records, which are prime targets for cybercriminals. The settlement fund covers legal fees, administrative costs, and compensation, with unclaimed amounts directed to cybersecurity-related nonprofits.
Source: https://www.claimdepot.com/settlements/keb-data-settlement
TPRM report: https://www.rankiteo.com/company/kerber-eck-and-braeckel
"id": "ker3362633101525",
"linkid": "kerber-eck-and-braeckel",
"type": "Breach",
"date": "2/2023",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '103,645 class members (U.S. '
'residents)',
'industry': 'Legal Services',
'name': 'Kerber, Eck & Braeckel LLP',
'type': 'Law Firm'}],
'customer_advisories': ['Claim deadline: 2025-11-25',
'Opt-out deadline: 2025-10-27',
'Fairness hearing: 2026-01-07',
'Contact: 1-866-742-4955 or '
'kebdatasettlement@rg2claims.com'],
'data_breach': {'data_exfiltration': 'Likely (data accessed/compromised)',
'number_of_records_exposed': '103,645',
'personally_identifiable_information': ['Names',
'Social Security '
'numbers',
'Addresses',
'Dates of birth',
'Driver’s license '
'numbers'],
'sensitivity_of_data': 'High (includes SSNs, medical, and '
'financial data)',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Protected Health Information '
'(PHI)',
'Financial Information']},
'date_detected': '2023-02',
'description': 'Kerber, Eck & Braeckel LLP experienced a cybersecurity '
'incident in February 2023 that exposed sensitive personal '
'information, including names, Social Security numbers, '
'addresses, dates of birth, driver’s license numbers, '
'financial account details, medical treatment information, and '
'health insurance information. The company agreed to a $1.4 '
'million class action settlement to resolve allegations of '
'inadequate data protection.',
'impact': {'brand_reputation_impact': 'Class action lawsuit and settlement; '
'potential reputational damage',
'customer_complaints': '103,645 class members (potentially '
'affected)',
'data_compromised': ['Names',
'Social Security numbers',
'Addresses',
'Dates of birth',
'Driver’s license numbers',
'Financial account details',
'Medical treatment information',
'Health insurance information'],
'financial_loss': {'administration_costs': 'TBD',
'attorneys_expenses': '$20,000',
'attorneys_fees': '$466,666.67 (33%)',
'class_member_payouts': {'credit_monitoring': '2 '
'years '
'(three-bureau)',
'pro_rata_cash_payment': 'Estimated '
'$50 '
'(subject '
'to '
'change)',
'unreimbursed_economic_losses': 'Up '
'to '
'$10,000 '
'per '
'claimant '
'(documented)'},
'cy_pres_recipients': ['Illinois State Bar '
'Association',
'St. Francis Care'],
'service_awards': '$15,000 (3 x $5,000)',
'settlement_fund': '$1,400,000'},
'identity_theft_risk': 'High (SSNs, financial, and medical data '
'exposed)',
'legal_liabilities': '$1.4 million settlement',
'payment_information_risk': 'High (financial account details '
'exposed)'},
'investigation_status': 'Settled (class action lawsuit; final approval '
'hearing scheduled for 2026-01-07)',
'post_incident_analysis': {'corrective_actions': ['$1.4M settlement fund for '
'affected individuals',
'Credit monitoring services '
'(2 years)',
'Reimbursement for economic '
'losses (up to $10,000)'],
'root_causes': ['Alleged failure to adequately '
'protect sensitive personal '
'information']},
'references': [{'source': 'KEB Data Incident Settlement Website'},
{'source': 'Settlement Administrator (RG/2 Claims '
'Administration)'}],
'regulatory_compliance': {'legal_actions': ['Class action lawsuit (settled '
'for $1.4M)']},
'response': {'communication_strategy': ['Notice sent to affected individuals',
'Online and mail-in claim forms',
'Dedicated helpline (1-866-742-4955) '
'and email '
'(kebdatasettlement@rg2claims.com)'],
'recovery_measures': ['Class action settlement ($1.4M)',
'Credit monitoring for affected '
'individuals'],
'third_party_assistance': ['RG/2 Claims Administration '
'(settlement administrator)']},
'stakeholder_advisories': ['Notice sent to 103,645 class members',
'Credit monitoring offered (2 years)',
'Pro rata cash payments ($50 estimated) or '
'reimbursement for economic losses (up to '
'$10,000)'],
'title': 'Kerber, Eck & Braeckel LLP Data Breach (February 2023)',
'type': ['Data Breach', 'Class Action Lawsuit']}