Social EngineeringPhishingStolen CredentialsTargetedData ExfiltratedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
PILLSBURY WINTHROP SHAW PITTMAN LLP
bd_0ba5f2f7e42e487f · schema v1 · pii pii-v1
Full breach record for PILLSBURY WINTHROP SHAW PITTMAN LLP →Pillsbury Winthrop Shaw Pitman LLP disclosed a security incident in late April 2025 where an unauthorized actor accessed firm documents following a social engineering attack. The firm engaged forensic investigators and notified law enforcement. Affected data includes personal information such as names and government IDs. The firm is offering 24 months of credit monitoring via Equifax.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_4d95cd9f800da5f4New Hampshire State AGfiled 2025-11-06Verified
- bd_b215afd6546944fcMontana State AGfiled 2025-11-06Candidate
- bd_b9c1fcb0d2856ca2Iowa State AGfiled 2025-11-06Verified
- bd_c6f6eef2131011f3Delaware State AGfiled 2025-11-06Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_dc43924c9e59e121Indiana State AGfiled 2025-11-06Verified
- bd_58a008bb40c21d44Texas State AGfiled 2025-11-07(1d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Consumer%20Letter%20-%20Pillbury%20Winthrop%20Shaw%20Pitman%20LLP.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 6, 2025
- Raw hash
- 453dd20967325db7036f519e30f2dc0f183d65895c854cff422d6c8b972fea2c
Reporting entity
- Name
- PILLSBURY WINTHROP SHAW PITTMAN LLPnorm: pillsbury winthrop shaw pittman
Victim entity
- Name
- PILLSBURY WINTHROP SHAW PITTMAN LLPnorm: pillsbury winthrop shaw pittman
Incident
- Discovered
- Apr 30, 2025
- Materiality determined
- —
- Notification sent
- Oct 23, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 27 weeks(190 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.