Rich & Henderson PC Data Breach Notice (Indiana Attorney General): What Was Exposed & What To Do
Rich & Henderson PC disclosed a data breach on June 25, 2026, involving the personal information of one individual; the incident itself occurred on August 13, 2025. Anyone who received a notice from the firm or who provided personal information to it should review the official filing with the Indiana Attorney General and consider placing a fraud alert or credit freeze.
Rich & Henderson PC notified Indiana residents of a data breach in a filing reported to the Indiana Attorney General on June 25, 2026. According to that filing, the incident itself occurred on August 13, 2025. The notice states that one person was affected and that personal information was involved. Public detail beyond those points is limited.
Even a notice covering a single individual matters because it confirms that personal data held by the firm was exposed and that state regulators were formally informed. For anyone connected to the firm, the practical question is what was involved and what steps reduce follow-on risk.
Breaking down the breach
The available record is the data-breach notice filed with the Indiana Attorney General and reported on June 25, 2026. That filing places the incident on August 13, 2025. It identifies Rich & Henderson PC as the organization, states that one person was affected, and describes the exposed data as personal information per the breach notification.
The filing does not publicly detail how the incident occurred, what systems were involved, whether data was encrypted, how long unauthorized access lasted, or whether information was viewed, copied, or removed. No threat actor is named in the disclosed material. Scale beyond the single reported individual, technical method, and any forensic findings remain undisclosed in the public summary.
What is established is the sequence of dates: an incident dated August 13, 2025, followed by a regulatory notice reported June 25, 2026, covering Indiana residents and listing one affected person.
How a breach like this happens
Incidents that lead to notices of this kind typically begin with unauthorized access to systems or accounts that store client or personnel records. Common pathways in professional-services environments include compromised credentials, phishing that yields login details, misdirected email, vulnerable remote-access tools, or malware on a workstation or server. Once access is obtained, an attacker may search for files containing names, contact details, identification numbers, or other personal data.
Organizations often discover such events through internal monitoring, unusual account activity, a vendor alert, or later investigation. After discovery, firms assess what records were involved, determine notification duties under state law, and file with attorneys general when required. The public notice usually confirms that personal information was implicated without always describing the precise technical entry point. No specific method or actor is attributed in the Rich & Henderson PC filing, so any description of technique remains general background rather than a finding about this case.
About Rich & Henderson PC
Rich & Henderson PC is a professional corporation. Firms structured this way commonly provide legal or similar professional services and maintain files on clients, matters, employees, and related parties. Those files routinely include contact information, correspondence, and other personal data needed to deliver services and meet regulatory or court requirements.
A breach at such an organization is consequential because the data it holds is often sensitive in context—tied to legal, financial, or personal matters—and because clients and others reasonably expect confidentiality. Even when only one person is listed as affected in a state filing, the notice signals that personal information under the firm’s control was exposed and that formal notification obligations were triggered.
The information in question
The breach notification names the exposed data as personal information. It does not itemize further categories such as Social Security numbers, financial account details, driver’s license numbers, medical information, or specific document types in the public summary provided.
Professional corporations of this kind typically hold names, addresses, phone numbers, email addresses, and other identifiers, and may also hold government ID numbers, financial or billing data, and case-related personal details depending on the work performed. Because the filing does not confirm which of those elements were involved beyond the general label “personal information,” the exact contents remain unconfirmed. Readers should treat only the stated category as established and regard any finer inventory as undisclosed.
What's at stake
For the affected individual, exposure of personal information can increase the risk of unwanted contact, social-engineering attempts, or identity-related misuse if enough identifying details were present. The concrete harm depends on what fields were actually involved—something the public notice does not spell out. Monitoring account statements, credit reports, and unexpected communications is a standard response when personal data may have been accessed.
For the organization, the stakes include regulatory notification duties, potential follow-up inquiries, reputational impact with clients, and the cost of investigation and remediation. A filing that reports a single affected person still requires careful handling of that individual’s data and clear communication about what is known and what remains limited.
No dollar losses, litigation outcomes, or findings of fault are stated in the disclosed facts. Those elements, if any, are outside the public summary used here.
Were you affected?
If you have a past or present relationship with Rich & Henderson PC and are concerned you may be the individual referenced, contact the firm through its official channels to ask whether your information was involved and what support it is offering. Review financial and credit activity for unfamiliar transactions or inquiries, and consider a fraud alert or credit freeze if you believe sensitive identifiers may have been exposed. Preserve any notice you receive and follow the specific instructions it contains.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets. That check does not replace official notice from the firm, but it can help you see whether your email has surfaced elsewhere and decide what additional monitoring is worthwhile.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
AssuranceAmerica Managing General Agency LLC Data Breach Notice (Indiana Attorney General)Travala Pte Ltd Data Breach Notice (Indiana Attorney General)American Vanguard Corporation Data Breach Notice (Indiana Attorney General)Kubota North America Corporation Data Breach Notice (Indiana Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.