MalwareRansomwareCapture Stored DataData ExfiltratedData EncryptedRansom DemandedPIIPHIIDENTITY_BASICLowContained
Troutman Pepper Hamilton Sanders LLP
bd_3f67dde8ca1ace85 · schema v1 · pii pii-v1
Full breach record for Troutman Pepper Hamilton Sanders LLP →Troutman Pepper Hamilton Sanders LLP disclosed a ransomware attack detected on February 8, 2023. The incident resulted in the unauthorized access and exfiltration of files containing personal and protected health information. The firm reported the incident to law enforcement, engaged outside cybersecurity experts, and offered 12 months of complimentary credit monitoring and fraud assistance to affected individuals.
Vermont clock✗ VT AG >45 bday43 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by black_basta about this victim predates this filing by 255 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_28a054e3a775be89Leak Siteblack_bastafiled 2023-03-23(255d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_23785f748b0bdd01California State AGfiled 2023-12-04Verified
- bd_5d30fecba2fb5887Montana State AGfiled 2023-12-04Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-04-troutman-pepper-hamilton-sanders-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 4, 2023
- Raw hash
- f3a2cef521e7070cacad5ab3674751107ff0709e310b9554f70f9da66fce5546
Reporting entity
- Name
- Troutman Pepper Hamilton Sanders LLPnorm: troutman pepper hamilton sanders
- Domain
- troutman.com
Victim entity
- Name
- Troutman Pepper Hamilton Sanders LLPnorm: troutman pepper hamilton sanders
- Domain
- troutman.com
Incident
- Discovered
- Feb 8, 2023
- Materiality determined
- Nov 15, 2023
- Notification sent
- Dec 4, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the incident to law enforcement
Compliance
- Time to disclose
- 43 weeks(299 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.