US Law Firm Suffers Large Scale Breach

Houser LLP a California-based law firm said that the ransomware attack it suffered in 2023 has compromised the sensitive personal information of more than 326,000 individuals.

Houser mainly caters to Fortune 500 companies. With more than ten offices across the country, the firm provides legal services to commercial businesses and financial institutions.

In a recent notice of data breach filed with the Office of the Maine Attorney, Houser said that in May last year, it discovered that malicious actors had encrypted certain files in its computer systems.

The firm immediately launched an investigation, with the assistance of third-party forensic specialists, to understand the nature and scope of the incident.

“The investigation determined that there was unauthorised access to the Houser network between May 7, 2023, and May 9, 2023, during which time certain files were copied and taken from the network.

However, in June 2023, the unauthorised actor informed Houser that they deleted copies of any stolen data and would not distribute any stolen files,” the firm has said.   

The law firm worked with cyber security experts to understand whether the files accessed by the threat actors contained any sensitive personal information of individuals associated with the firm.
The investigation, concluded on January 18, revealed that the malicious actors were able to access personal information such as names and other personal identifiers, financial account numbers, credit and debit card numbers along with security codes, access codes, passwords and PINs.

The filing with the state regulator also revealed that the data security incident compromised the personal information of at least 326,386 individuals.

“Houser takes the confidentiality, privacy, and security of information in our care seriously. Upon discovery, we immediately commenced an investigation to confirm the nature and scope of the incident,” the firm said.

“We reported this incident to law enforcement. We also took steps to implement additional safeguards policies and procedures relating to data privacy, security and our network environment. These additional safeguards include, but are not limited to, deployment of RocketCyber, an endpoint detection and response tool.

“We also implemented multi-factor authentication for Outlook 365, NetExtender VPN tunnel and remote desktop connection.

“We also added ransomware detection software, implemented the use of phishing simulation software and conducted vulnerability assessment and penetration testing,” Houser added.

The company has urged all affected individuals to remain vigilant, review their credit reports and financial statements on a regular basis, and report suspicious transactions to relevant law enforcement authorities.

It is also offering one year of complimentary credit monitoring and identity theft restoration through IDX to all the individuals affected by the data breach. Also, it has set up a dedicated helpline where affected individuals can call and get their queries answered.

On May 10 2023, the notorious ALPHV/BlackCat ransomware group claimed responsibility for the cyber attack on Houser LLP and listed the company as a victim on its data leak site.

The group claimed to be in possession of 1.5TB of company data including internal company data, employees personal data, CVs, DLs, IDs, SSNs, financial reports, agreements, insurance, client documentation including DLs, IDs, SSNs, financial data, credit card information, loan data, agreements, complete network map including credentials for local and remote services, and more.

TEISS     |     Maine Attorney General     |     Reuters     |     The Record     |     Law 360

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible

« The US Military Wants New AI Chips
AI Controlled Robotic Ships Set Sail »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Varonis

Varonis

Varonis provide a security software platform to let organizations track, visualize, analyze and protect their unstructured data.

Axial

Axial

Axial Systems is one of the UK’s leading solution providers and systems integrators in network, security and services.

ZeroFox

ZeroFox

ZeroFox safeguards modern organizations from dynamic security risks across social, mobile, surface, deep and dark web, email and collaboration platforms.

ElcomSoft

ElcomSoft

ElcomSoft is a global leader in computer and mobile forensics, IT security and forensic data recovery.

LIFARS

LIFARS

LIFARS is a global leader in Digital Forensics and Cyber Resiliency Services.

Cybersecurity Advisors Network (CyAN)

Cybersecurity Advisors Network (CyAN)

CyAN provides a not-for-profit platform that helps private and public organisations as well as governments to identify trusted advisors in the area of Cyber Security and Cyber Crime.

Office of the Government Chief Information Officer (OGCIO) - Hong Kong

Office of the Government Chief Information Officer (OGCIO) - Hong Kong

OGCIO supports the development of community-wide information technology infrastructure and setting of technical and professional standards to strengthen Hong Kong’s position as a world digital city.

American Cybersecurity Institute

American Cybersecurity Institute

American cybersecurity Institute is a newly formed not-for-profit organization dedicated to education, advocacy, study and analysis in the space of cybersecurity law and policy.

Thridwayv

Thridwayv

Thirdwayv helps your enterprise realize the full potential of loT connectivity. All while neutralizing security threats that can run ruin the customer experience - and your reputation.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

UST

UST

UST is a global provider of digital technology and transformation, IT services and solutions including managed security services.

Nexon Asia Pacific

Nexon Asia Pacific

Nexon solutions include cloud infrastructure and services, unified communications, managed security services, business continuity, secured high-performance network and business applications.

Sure Valley Ventures

Sure Valley Ventures

Sure Valley Ventures is an entrepreneur led venture capital fund focused on helping software entrepreneurs grow and scale businesses that will have a global impact.

Singtel Innov8

Singtel Innov8

Singtel Innov8, the venture capital arm of the Singtel Group, invests in and partners with innovative technology start-ups globally.

Imprivata

Imprivata

Imprivata is the digital identity company for life- and mission-critical industries, redefining how organizations solve complex workflow, security, and compliance challenges.

Allot

Allot

Allot are a global provider of leading innovative network intelligence and security solutions for Service Providers and Enterprises worldwide.