Slaughter and May

Slaughter and May

Detailed and potentially sensitive information uploaded by firm Slaughter and May was left exposed on an open database platform.

The cache of data, which included Companies House forms, partial security authentication details, business email addresses, and encrypted passwords, were accessible on a historic database owned and operated by British tech giant Advanced Computer Software.

Source: https://www.law.com/legaltechnews/2020/05/05/data-from-hundreds-of-law-firms-left-exposed-on-open-platform-397-33795/?kw=Data%20from%20Hundreds%20of%20Law%20Firms%20Left%20Exposed%20on%20Old%20Database%2C%20Report%20Says&slreturn=20221129105550

TPRM report: https://scoringcyber.rankiteo.com/company/slaughter-and-may

"id": "sla029301222",
"linkid": "slaughter-and-may",
"type": "Data Leak",
"date": "05/2020",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Legal Services',
                        'name': 'Slaughter and May',
                        'type': 'Law Firm'}],
 'attack_vector': 'Open Database',
 'data_breach': {'data_encryption': 'Encrypted passwords',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Companies House forms',
                                              'Partial security authentication '
                                              'details',
                                              'Business email addresses',
                                              'Encrypted passwords']},
 'description': 'Detailed and potentially sensitive information uploaded by '
                'firm Slaughter and May was left exposed on an open database '
                'platform. The cache of data, which included Companies House '
                'forms, partial security authentication details, business '
                'email addresses, and encrypted passwords, were accessible on '
                'a historic database owned and operated by British tech giant '
                'Advanced Computer Software.',
 'impact': {'data_compromised': ['Companies House forms',
                                 'Partial security authentication details',
                                 'Business email addresses',
                                 'Encrypted passwords']},
 'title': 'Sensitive Data Exposure by Slaughter and May',
 'type': 'Data Exposure'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.