Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Law Firm Orrick Reveals Extensive Data Breach, Over Half a Million Affected

Global law firm Orrick, Herrington & Sutcliffe disclosed a data breach that affects a roughly 600,000 individuals.

Orrick, Herrington & Sutcliffe, a law firm that specializes in cyberattacks, last week disclosed that more than 600,000 individuals were impacted by a data breach that happened in early 2023.

Between February 28 and March 13, 2023, the company said attackers had unauthorized access to a portion of its network, including a file share storing files related to Orrick’s clients.

“Orrick has identified no evidence of further unauthorized activity since detecting the security incident on March 13,” the company said.

Orrick said its analysis of the exposed files determined that personal information pertaining to the customers of its clients was compromised in the attack, and that notification letters were sent to the impacted individuals starting June 2023.

Some of these individuals, the law firm said, were customers of companies that suffered data breaches. Their information was shared with Orrick to facilitate the provision of legal counseling to those companies.

The compromised personal information includes names, addresses, dates of birth, Social Security numbers, driver’s license or other government ID numbers, passport numbers, email addresses, financial account details, tax identification numbers, medical and health information, health insurance and healthcare provider details, online account credentials, and credit or debit card numbers.

“Orrick deployed additional security measures and tools with the guidance of third-party experts to strengthen the ongoing security of its network. Orrick is not aware of any misuse of the affected personal information,” the company said.

Orrick informed the Maine AGO that the incident impacted close to 638,000 individuals, customers of entities such as Carelon (previously Beacon Health Options), Delta Dental, EyeMed Vision Care, MultiPlan, and US Small Business Administration.

Advertisement. Scroll to continue reading.

In December, the law firm said it had reached a tentative settlement in four class action suits related to the data breach, Reuters reported.

Founded in San Francisco in 1863, Orrick provides counseling on transactions, litigation, and regulatory matters for financial, government, infrastructure, technology, and other types of organizations.

Related: 4.5 Million Affected by Data Breach at HealthEC

Related: Estes Express Lines Suffers Ransomware Attack

Related: Massive Data Breach at Defunct Boston Ambulance Service

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn about active threats targeting common cloud deployments and what security teams can do to mitigate them.

Register

Join us for an in depth exploration of the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects.

Register

Expert Insights

Related Content

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.

Data Breaches

A group of hackers has leaked Atlassian employee records and floorplans, information that was obtained from third-party workplace platform Envoy.

Data Breaches

Sony shares information on the impact of two recent unrelated hacker attacks carried out by known ransomware groups. 

Data Breaches

KFC and Taco Bell parent company Yum Brands says personal information was compromised in a January 2023 ransomware attack.

Data Breaches

AT&T is notifying millions of wireless customers that their CPNI was compromised in a data breach at a third-party vendor.