GOODWIN PROCTER LLP
bd_b9c409173de26b15 · schema v1 · pii pii-v1
Full breach record for GOODWIN PROCTER LLP →4 incidents on fileGoodwin Procter LLP notified Vermont AG of a cybersecurity incident affecting client personal information (names, SSNs, DOBs, passports, addresses). The intrusion occurred on April 29, 2025, via a third-party technology provider, Commvault, and was contained on May 2, 2025. Goodwin updated credentials, engaged forensic experts, notified law enforcement, and offered 24 months of credit monitoring. No evidence of continued access was found.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 29, 2025
Begins
May 2, 2025
Discovered
Jul 6, 2025
Filed
vs. sector median
9 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- New Hampshire State AGbd_1a5ecb1ab228a8672025-07-07 · +1dVerified
- Maine State AGbd_55f8d93357aa2b372025-07-02 · +4dCandidate
- Indiana State AGbd_713da412b4b3b6702025-07-02 · +4dVerified
- Massachusetts State AGbd_7cfa5fa5c60bf3732025-07-02 · +4dVerified
Show 1 more filing ↓Show fewer ↑up to 4d gap
- Nebraska State AGbd_86ae7a372ba634062025-07-02 · +4dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Jul 2 (ME), last Jul 7 (NH) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.