Top legal firm specializing in data breaches...hit by data breach

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

A top legal firm that specializes in helping other organizations in the aftermath of a data breach has ironically suffered one such incident itself.

Orrick, Herrington & Sutcliffe has sent out a breach notification letter to affected individuals, confirming it had been the victim of an intrusion that happened in March 2023. 

Usually, the company helps other victims remain compliant with state laws and regulations regarding data management, privacy, and communication. Among other things, the company collects victim information and uses it to notify state authorities.

Missing key details

It was this very data that the hackers made away with. Orrick claims threat actors stole people’s names, birth dates, postal and email addresses, Social Security Numbers (SSN), driver’s license numbers, and tax identification numbers. Furthermore, online account credentials, as well as credit and debit card numbers, were also taken.

Finally, hackers took data on medical treatment and diagnosis, insurance claims, insurance numbers, and more. 

The victims include people with vision plans at EyeMed Vision Care, dental plans with Delta Dental, as well as those using MultiPlan, Beacon Health Options, and the U.S. Small Business Administration. In total, at least 637,000 people were affected.

Despite the large scale of the incident, some important details remain omitted. For example, we don’t know who the threat actors are, or how they infiltrated the company’s infrastructure (via malware, or social engineering, for example). We also don’t know if this was a ransomware attack and, if so, what the demands are, and whether the company plans on paying them or not. 

Issuing a statement to TechCrunch, Orrick spokesperson Jolie Goldstein said: “We regret the inconvenience and distraction that this malicious incident caused. We made it our priority to resolve it as quickly as possible for our clients, the individuals whose data was impacted, and our team.”

Via TechCrunch

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Representational image depecting cybersecurity protection
Top venture capital firm Insight Partners confirms it was hit by cyberattack
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
Closing the cybersecurity skills gap
HPE starts contacting victims of 2023 Russian cyberattack
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Latest in Security
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Latest in News
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Millwall FC The Den
The UK's first football club mobile network is here - but you probably won't guess which team has launched it
Android Auto
Android Auto 14.0 is rolling out now – and it'll soon swap Google Assistant for the smarter Gemini
The Witcher 4
You're probably not playing The Witcher 4 until 2027 at the earliest, per CD Projekt's latest financial update