The State Bar of Georgia was hit by a ransomware attack earlier this year and the organization has now confirmed that member and employee information was compromised.
The incident occured in April 2022 and was disclosed in early May, when few details were shared by the organization. Roughly one month later, the bar revealed that the attack involved BitLocker ransomware, which encrypted tens of servers and workstations.
“Although this has been officially described as a ransomware attack, no monetary demand has been made and no proof of possession of any personally identifiable information or other data has been provided,” a State Bar of Georgia representative said at the time.
The bar initially said there was no evidence that personal information had been compromised, but a statement released last week revealed that some information on current and former employees, as well as members, may have been obtained by the attacker.
Exposed personal information includes names, addresses, dates of birth, social security numbers, driver’s license numbers, direct deposit information, or name change information.
“Although we had security protocols and technology in place to help prevent unauthorized access, some of those defenses were evaded,” the bar said.
Every individual authorized to practice law in the State of Georgia is required to be a member, and the organization claims to have more than 50,000 members.
Impacted individuals are being offered free credit monitoring and identity protection services.
Related: Idaho Man Charged With Hacking Into Computers in Georgia
Related: Georgia Man Admits to Hacking Accounts of Athletes and Musicians
Related: Georgia Supreme Court Rules that State Has No Obligation to Protect Personal Information

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- High-Severity Privilege Escalation Vulnerability Patched in VMware Workstation
- GoAnywhere MFT Users Warned of Zero-Day Exploit
- UK Car Retailer Arnold Clark Hit by Ransomware
- EV Charging Management System Vulnerabilities Allow Disruption, Energy Theft
- Unpatched Econolite Traffic Controller Vulnerabilities Allow Remote Hacking
- Google Fi Data Breach Reportedly Led to SIM Swapping
- Microsoft’s Verified Publisher Status Abused in Email Theft Campaign
- British Retailer JD Sports Discloses Data Breach Affecting 10 Million Customers
Latest News
- US Downs Chinese Balloon Off Carolina Coast
- Microsoft: Iran Unit Behind Charlie Hebdo Hack-and-Leak Op
- Feds Say Cyberattack Caused Suicide Helpline’s Outage
- Big China Spy Balloon Moving East Over US, Pentagon Says
- Former Ubiquiti Employee Who Posed as Hacker Pleads Guilty
- Cyber Insights 2023: Venture Capital
- Atlassian Warns of Critical Jira Service Management Vulnerability
- High-Severity Privilege Escalation Vulnerability Patched in VMware Workstation
