Drost Kivlahan McMahon & O'Connor LLC
bd_ad42d877b2791beb · schema v1 · pii pii-v1
Full breach record for Drost Kivlahan McMahon & O'Connor LLC →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group BianLian on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Drost Kivlahan McMahon & O'Connor LLC has been establishing lasting relationships with individuals and businesses since 1987. The firm's success is based on the professional and efficient representation of each client in a convenient and friendly atmosphere. The cornerstone of the practice is the firm's ability to respond to client needs in a timely and practical manner while providing high quality legal services.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Feb 9, 2024
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- Illinois State AGbd_13a9d7461e7394a22024-08-01 · +173dVerified by operator
- Maine State AGbd_06cf8f5a53ec4a462024-08-29 · +201dVerified
- Montana State AGbd_4092b2b66591e42b2024-08-29 · +201dVerified
- Massachusetts State AGbd_60d7ee977e50e02d2024-08-29 · +201dVerified by operator
Show 3 more filings ↓Show fewer ↑up to 201d gap
- New Hampshire State AGbd_80bff10e0475a3a32024-08-29 · +201dVerified
- Vermont State AGbd_93443d977d8450b82024-08-29 · +201dVerified
- Indiana State AGbd_9f7fbabc75af16a72024-08-29 · +201dVerified
Filing propagation · 8 filings · 7 states
View merged incident ↗Pattern: first filing Feb 9, last Aug 29 (IN) — a 201-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
bianlian
According to ransomware.live, BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog.