The Vermont Office of the Attorney General disclosed a ransomware attack targeting Eckell Sparks, discovered on August 22, 2024, but originating around November 21, 2023. The incident led to the potential compromise of sensitive personal data, specifically Dates of Birth and Social Security Numbers of affected individuals. While the full scope of the breach remains under investigation, the exposure of such highly confidential information poses severe risks, including identity theft, financial fraud, and long-term reputational harm for the firm. Ransomware attacks of this nature often involve data encryption and exfiltration, meaning threat actors may have not only disrupted operations but also stolen critical records for malicious use. The breach underscores vulnerabilities in cybersecurity defenses, particularly against sophisticated ransomware strains that exploit system weaknesses to infiltrate and extract valuable data. Legal and regulatory repercussions, such as fines or lawsuits, may follow due to the failure to protect personally identifiable information (PII).
Source: https://ago.vermont.gov/document/2024-08-22-eckell-sparks-data-breach-notice-consumers
TPRM report: https://www.rankiteo.com/company/eckell-sparks-levy-auerbach
"id": "eck604090125",
"linkid": "eckell-sparks-levy-auerbach",
"type": "Ransomware",
"date": "11/2023",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'industry': 'Legal Services',
'name': 'Eckell Sparks',
'type': 'Law Firm'}],
'data_breach': {'personally_identifiable_information': ['Date of Birth',
'Social Security '
'Number'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)']},
'date_publicly_disclosed': '2024-08-22',
'description': 'The Vermont Office of the Attorney General reported a data '
'breach involving Eckell Sparks on August 22, 2024. The breach '
'occurred on or about November 21, 2023, due to a ransomware '
'incident, potentially compromising personal information '
'including Date of Birth and Social Security Number.',
'impact': {'data_compromised': ['Date of Birth', 'Social Security Number'],
'identity_theft_risk': 'High (PII exposed)'},
'references': [{'date_accessed': '2024-08-22',
'source': 'Vermont Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': ['Vermont Office of the '
'Attorney General']},
'title': 'Data Breach at Eckell Sparks Due to Ransomware Incident',
'type': 'Data Breach (Ransomware)'}