HackingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
Orrick, Herrington & Sutcliffe LLP
bd_2ee611114ebad362 · schema v1 · pii pii-v1
Full breach record for Orrick, Herrington & Sutcliffe LLP →Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to a portion of its network on March 10, 2023. The breach was detected on March 13, 2023. Files containing personal information of plan participants, including health insurance data, were accessed. Orrick engaged cybersecurity experts, notified law enforcement, and is offering two years of identity monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576355
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 9, 2023
- Raw hash
- 12f243b1129987dda10ebbfdbda74d475dab3735adbe2658ec4db9f446180514
Reporting entity
- Name
- Orrick, Herrington & Sutcliffe LLPnorm: orrick herrington sutcliffe
- Domain
- orrick.com
Victim entity
- Name
- Orrick, Herrington & Sutcliffe LLPnorm: orrick herrington sutcliffe
- Domain
- orrick.com
Incident
- Discovered
- Mar 13, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
Compliance
- Time to disclose
- 34 weeks(241 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.