HackingTargetedIDENTITY_BASICPIILowContained
Cadwalader Wickersham Taft
bd_06bded7996e894f6 · schema v1 · pii pii-v1
Full breach record for Cadwalader Wickersham Taft →Cadwalader, Wickersham & Taft LLP notified consumers of a cybersecurity incident occurring November 15-16, 2022, where an unauthorized third party gained remote access to systems and acquired personal information including names. The firm engaged forensic experts, reported to law enforcement, and provided two years of identity monitoring services via Kroll. No evidence of misuse was found at the time of notice.
Vermont clock✗ VT AG >45 bday19 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_fc9508fac3be4135Montana State AGfiled 2023-03-30Candidate
- bd_5c2e0c62e080c473New Hampshire State AGfiled 2023-04-04(5d gap)Verified
- bd_577b43209646d015California State AGfiled 2023-04-06(7d gap)Verified
- bd_5fad6b8232a42c31Maine State AGfiled 2023-04-06(7d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 110d gap
- bd_733e0cf21da3dc94California State AGfiled 2023-07-18(110d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-03-30-cadwalader-wickersham-taft-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 30, 2023
- Raw hash
- de7ccd446e5df3b3d7660d854a6d95887c959007a92264f21c109b57b5a6a7e2
Reporting entity
- Name
- Cadwalader Wickersham Taftnorm: cadwalader wickersham taft
Victim entity
- Name
- Cadwalader Wickersham Taftnorm: cadwalader wickersham taft
Incident
- Discovered
- Nov 16, 2022
- Materiality determined
- —
- Notification sent
- Mar 30, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported this incident to law enforcement and relevant regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(134 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.