MalwareRansomwareData EncryptedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTPIIMediumContained
Eckell, Sparks, Levy, Auerbach, Monte, Sloane, Matthews & Auslander, P.C
bd_046cecae47c54f20 · schema v1 · pii pii-v1
Full breach record for Eckell, Sparks, Levy, Auerbach, Monte, Sloane, Matthews & Auslander, P.C →Eckell Sparks, a law firm, disclosed a ransomware incident occurring on November 21, 2023. The breach compromised personal information including dates of birth and Social Security Numbers, as well as privileged legal communications. The firm engaged forensic investigators, notified the FBI, and offered 12 months of credit monitoring to affected individuals.
Vermont clock✗ VT AG >45 bday39 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by alphv about this victim predates this filing by 357 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_ea25c96fcbea9d6fMontana State AGfiled 2024-08-21(1d gap)Candidate
- bd_e2db7d46c30da3f3Indiana State AGfiled 2024-08-19(3d gap)Verified
- bd_8f628ea1b589d219New Hampshire State AGfiled 2024-08-27(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-08-22-eckell-sparks-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 22, 2024
- Raw hash
- 0ea8353758f2fe50724542ab111717a456fc5cd63d35a38f0d238ecd43e747d7
Reporting entity
- Name
- Eckell, Sparks, Levy, Auerbach, Monte, Sloane, Matthews & Auslander, P.Cnorm: eckell sparks levy auerbach monte sloane matthews auslander
- Domain
- eckellsparks.com
Victim entity
- Name
- Eckell, Sparks, Levy, Auerbach, Monte, Sloane, Matthews & Auslander, P.Cnorm: eckell sparks levy auerbach monte sloane matthews auslander
- Domain
- eckellsparks.com
Incident
- Discovered
- Nov 21, 2023
- Materiality determined
- —
- Notification sent
- Aug 19, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed a report with the FBIProviding notice to privacy regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 39 weeks(275 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.