The legal practice Orrick, Herrington & Sutcliffe revealed a breach of data that affected 638,000 people.
An authorised actor obtained access to the company network. The files pertaining to the legal firm's clients were accessible to the hackers thanks to a storage unit.
Name, address, email address, date of birth, Social Security number, passport number, driver's licence number, or other government-issued identification number, financial account information, tax identification number, information about medical treatment and/or diagnosis, information about claims (date, cost of services, and claim identifiers), and health insurance are among the details that have been compromised.
Orrick explained that it immediately took steps to block the unauthorized access and launched an investigation into the security incident.
Source: https://securityaffairs.com/156985/breaking-news/law-firm-orrick-data-breach.html
TPRM report: https://scoringcyber.rankiteo.com/company/orrick
"id": "orr6217124",
"linkid": "orrick",
"type": "Breach",
"date": "03/2023",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 638000,
'industry': 'Legal',
'name': 'Orrick, Herrington & Sutcliffe',
'type': 'Legal Practice'}],
'attack_vector': 'Network Access',
'data_breach': {'number_of_records_exposed': 638000,
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personal Information',
'Financial Information',
'Health Information']},
'description': 'An authorized actor obtained access to the company network. '
"The files pertaining to the legal firm's clients were "
'accessible to the hackers thanks to a storage unit. Sensitive '
'personal and financial information was compromised.',
'impact': {'data_compromised': ['Name',
'Address',
'Email address',
'Date of birth',
'Social Security number',
'Passport number',
"Driver's licence number",
'Other government-issued identification '
'number',
'Financial account information',
'Tax identification number',
'Information about medical treatment and/or '
'diagnosis',
'Information about claims (date, cost of '
'services, and claim identifiers)',
'Health insurance']},
'investigation_status': 'Launched an investigation into the security '
'incident.',
'response': {'containment_measures': 'Orrick explained that it immediately '
'took steps to block the unauthorized '
'access and launched an investigation '
'into the security incident.'},
'threat_actor': 'Authorized Actor',
'title': 'Orrick, Herrington & Sutcliffe Data Breach',
'type': 'Data Breach'}