US Law Firm Suffers Large Scale Breach

Houser LLP a California-based law firm said that the ransomware attack it suffered in 2023 has compromised the sensitive personal information of more than 326,000 individuals.

Houser mainly caters to Fortune 500 companies. With more than ten offices across the country, the firm provides legal services to commercial businesses and financial institutions.

In a recent notice of data breach filed with the Office of the Maine Attorney, Houser said that in May last year, it discovered that malicious actors had encrypted certain files in its computer systems.

The firm immediately launched an investigation, with the assistance of third-party forensic specialists, to understand the nature and scope of the incident.

“The investigation determined that there was unauthorised access to the Houser network between May 7, 2023, and May 9, 2023, during which time certain files were copied and taken from the network.

However, in June 2023, the unauthorised actor informed Houser that they deleted copies of any stolen data and would not distribute any stolen files,” the firm has said.   

The law firm worked with cyber security experts to understand whether the files accessed by the threat actors contained any sensitive personal information of individuals associated with the firm.
The investigation, concluded on January 18, revealed that the malicious actors were able to access personal information such as names and other personal identifiers, financial account numbers, credit and debit card numbers along with security codes, access codes, passwords and PINs.

The filing with the state regulator also revealed that the data security incident compromised the personal information of at least 326,386 individuals.

“Houser takes the confidentiality, privacy, and security of information in our care seriously. Upon discovery, we immediately commenced an investigation to confirm the nature and scope of the incident,” the firm said.

“We reported this incident to law enforcement. We also took steps to implement additional safeguards policies and procedures relating to data privacy, security and our network environment. These additional safeguards include, but are not limited to, deployment of RocketCyber, an endpoint detection and response tool.

“We also implemented multi-factor authentication for Outlook 365, NetExtender VPN tunnel and remote desktop connection.

“We also added ransomware detection software, implemented the use of phishing simulation software and conducted vulnerability assessment and penetration testing,” Houser added.

The company has urged all affected individuals to remain vigilant, review their credit reports and financial statements on a regular basis, and report suspicious transactions to relevant law enforcement authorities.

It is also offering one year of complimentary credit monitoring and identity theft restoration through IDX to all the individuals affected by the data breach. Also, it has set up a dedicated helpline where affected individuals can call and get their queries answered.

On May 10 2023, the notorious ALPHV/BlackCat ransomware group claimed responsibility for the cyber attack on Houser LLP and listed the company as a victim on its data leak site.

The group claimed to be in possession of 1.5TB of company data including internal company data, employees personal data, CVs, DLs, IDs, SSNs, financial reports, agreements, insurance, client documentation including DLs, IDs, SSNs, financial data, credit card information, loan data, agreements, complete network map including credentials for local and remote services, and more.

TEISS     |     Maine Attorney General     |     Reuters     |     The Record     |     Law 360

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible

« The US Military Wants New AI Chips
AI Controlled Robotic Ships Set Sail »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Secure Identity Alliance (SIA)

Secure Identity Alliance (SIA)

The Secure Identity Alliance is dedicated to supporting sustainable worldwide economic growth and prosperity through the development of trusted digital identities and the adoption of secure eServices.

QATestLab

QATestLab

QATestLab is a leading International software testing company offering a full range of software testing services including security testing.

BSA - The Software Alliance

BSA - The Software Alliance

BSA is the leading advocate for the global software industry before governments and in the international marketplace.

AMETIC

AMETIC

AMETIC, is the Association of Electronics, Information and Communications Technologies, Telecommunications and Digital Content Companies in Spain.

IT Association of Slovakia (ITAS)

IT Association of Slovakia (ITAS)

ITAS is a professional association of domestic and foreign companies operating in the field of information and communication technologies

Trustonic

Trustonic

Trustonic is a leader in the device security market. Our mission is to protect apps, secure devices & enable trust.

Halcyon Knights

Halcyon Knights

Halcyon Knights is a specialist executive search and IT recruitment agency in the APAC region. Areas of specialisation include cybersecurity.

Red Alert Labs

Red Alert Labs

Red Alert Labs is an IoT security provider. We created an independent security lab with a disruptive business offer to solve the technical and commercial challenges in IoT.

Risk Based Security (RBS)

Risk Based Security (RBS)

Risk Based Security provide the most comprehensive and timely vulnerability intelligence, breach data and risk ratings.

Elron Ventures

Elron Ventures

Elron partner with early stage ventures to build companies that transform lives and industries. Our main areas of focus are enterprise software, cybersecurity, and healthcare.

Cyberspace Solarium Commission (CSC)

Cyberspace Solarium Commission (CSC)

The Cyberspace Solarium Commission was established to develop a consensus on a strategic approach to defending the United States in cyberspace against cyber attacks of significant consequences.

Red River

Red River

Red River is a technology transformation company, bringing 25 years of experience and mission-critical expertise in analytics, cloud, collaboration, mobility, networking and security solutions.

Kocho

Kocho

Kocho (formerly TiG) is a provider of identity and access, cyber security, cloud transformation, and managed IT services.

CyberHunter Solutions

CyberHunter Solutions

CyberHunter is a leading website security company that provides penetration testing, Network Vulnerability Assessments, cyber security consulting services to prevent cyber attacks.

Conversant Group

Conversant Group

Conversant Group is an IT infrastructure and security consulting company, providing technical, organizational, procedural, and process consulting internationally.

SecOps Group

SecOps Group

SecOps Group is a boutique cybersecurity consultancy helping enterprises identify & eliminate security risks on a continuous basis.