Bojangles and law firm Blank Rome are facing class-action litigation after separate breaches exposed sensitive personal data. In North Carolina, a Business Court judge ruled that a lawsuit over Bojangles’ 2024 employee breach can proceed in state court after a similar federal case was dismissed. The suit, filed by nine former employees on behalf of other affected workers, alleges that hackers tied to Hunters International stole more than 387,000 files totaling over 290 GB and later posted data on the dark web, including Social Security numbers and other employee information.
Blank Rome was hit with two proposed class actions after a May breach allegedly affected more than 57,000 current, former, and prospective clients. The firm said the incident began with a social-engineering attack in which a cybercriminal impersonated the IT department and persuaded an attorney to upload files to an external hosting site. Plaintiffs allege the firm lacked adequate cybersecurity controls and employee training, delayed notification for more than a month after the May 21 incident, and exposed personal, financial, and health-related information.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
A North Carolina Business Court judge ruled that the class-action lawsuit over Bojangles' 2024 employee data breach can proceed in state court. The decision marked a reversal from the earlier federal-court dismissal described in the article.
Blank Rome became the target of two lawsuits over the May data breach affecting more than 57,000 clients. The complaints allege inadequate cybersecurity safeguards, insufficient employee training, and delayed notification to affected individuals.
In 2025, litigation over the Bojangles employee data breach was dismissed in federal court. The article says plaintiffs later found more success pursuing the matter in North Carolina state court.
In January 2025, nine former Bojangles employees filed a lawsuit on behalf of themselves and other affected workers over the company's 2024 employee data breach. The suit sought relief for the exposure of sensitive employee information.
In 2024, Bojangles suffered an employee data breach linked in the article to the Russian hacking group Hunters International. The attackers allegedly stole more than 387,000 files and over 290 GB of data, including employees' Social Security numbers and other personal information, and posted sensitive data on the dark web.
On 2026-05-21, Blank Rome LLP says a cybercriminal impersonated the firm's IT department and convinced an attorney to upload files to an external file-hosting site. The incident allegedly exposed personal information belonging to more than 57,000 current, former, and prospective clients.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.