Depends on the size of the company and if you can convince the lawyer to do it on his own dime. He could then subpoena customer records and inquire if anyone else has had security issues. How did the security problem happen and how could it have been prevented? No matter what the shrink wrap service licence says their are implied minimum standards and expectations. If people aren't getting what they think they are paying for then it should merit a class action.
Just this act might make it worth it to you to pay the lawyer yourself. Maybe $500 or $1000. It would get the companies attention. You would have their complete customer list and be emailing all their customer pasts and current asking for people to come forward with security issues. Just that act would bring awareness of the issue to other customers and have them asking the provider about security and guarantees.
The company will talk to you before they hand over customer records. You can likely negotiate to pay your minimal legal costs and to work with you and actually fix their security procedures. You might even be able to get a couple grand compensation in exchange for working with you to fix THEIR security issues.
Another thing you can do is write senators and congressmen and bring attention to the issue. Suggest a minimum penalty that companies are liable for, like $500 or $1000. Something that would make companies pay attention and not sacrifice security for convenience.