HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSEMPLOYMENTMediumContained
Kirkland & Ellis LLP
bd_02237a7cc8f297a4 · schema v1 · pii pii-v1
Full breach record for Kirkland & Ellis LLP →Kirkland & Ellis LLP notified individuals of a data breach resulting from a cybersecurity issue in Progress Software's MOVEit Transfer solution. Between May 27 and May 31, 2023, an unauthorized third party accessed files transferred via the tool. Affected data included names, contact info, SSNs, financial account details, health info, credentials, and employment data. The firm engaged cybersecurity experts, notified law enforcement, and offered 24 months of credit monitoring.
California clockDiscovered May 31, 2023 → Notified May 28, 2024363d ✗ CA 60-day late13 months discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_76e20d53b936d6ebMontana State AGfiled 2024-06-12Candidate
- bd_0f2b6129de255d01Vermont State AGfiled 2024-05-28(15d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-586862
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 12, 2024
- Raw hash
- c63d04b6b2b36ca32432ed2873dd9bfc10e6e71b480dd440ededba161ef1f0bc
Reporting entity
- Name
- Kirkland & Ellis LLPnorm: kirkland ellis
- Domain
- kirkland.com
Victim entity
- Name
- Kirkland & Ellis LLPnorm: kirkland ellis
- Domain
- kirkland.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- May 28, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported the issue to law enforcement
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 13 months(378 days from discovery to filing)
- Compliance flags
- CA 60-day late · 363dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: May 28, 2024363d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.