GOODWIN PROCTER LLP
bd_1a5ecb1ab228a867 · schema v1 · pii pii-v1
Full breach record for GOODWIN PROCTER LLP →4 incidents on fileGoodwin Procter LLP notified NH AG of a cybersecurity incident resulting from a third-party provider (Commvault) breach. Unauthorized access occurred April 29-May 1, 2025, using compromised credentials to access select email accounts. Personal information (name, SSN, DOB, passport) of 4 NH residents was exposed. Goodwin contained the incident, engaged forensic experts, notified law enforcement, and is offering 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 29, 2025
Begins
May 2, 2025
Discovered
Jun 6, 2025
Scope determined
Jul 7, 2025
Filed
vs. sector median
9 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Vermont State AGbd_b9c409173de26b152025-07-06 · +1dVerified
- Maine State AGbd_55f8d93357aa2b372025-07-02 · +5dCandidate
- Indiana State AGbd_713da412b4b3b6702025-07-02 · +5dVerified
- Massachusetts State AGbd_7cfa5fa5c60bf3732025-07-02 · +5dVerified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- Nebraska State AGbd_86ae7a372ba634062025-07-02 · +5dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Jul 2 (ME), last Jul 7 (NH) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.