Social EngineeringProfessional ServicesProfessional ServicesPhishingStolen CredentialsCapture Stored DataTargetedMulti-Stage ChainData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIILowResolved
Covington & Burling LLP
bd_ef4870e4484ddb51 · schema v1 · pii pii-v1
Full breach record for Covington & Burling LLP →On February 26, 2024, a Covington & Burling LLP employee was targeted by a spear-phishing attack, enabling an unauthorized actor to access the employee's workstation for several hours and copy data that included personal information obtained in connection with legal services. The data review was completed on June 3, 2024. 2 Maine residents and 35 total individuals were affected. Covington offered 24-month Experian IdentityWorks monitoring and notified law enforcement.
Maine clockDiscovered Jun 3, 2024 → Filed with AG Jul 1, 202428d ✓ ME AG ≤30d28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/2b2ea34f-ef2e-49f3-ae6f-6e888a07d002.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2024
- Raw hash
- b6d035413dac9867d3eb7c56d205da1925a5065aa392a7ac76eeb959678274bf
Reporting entity
- Name
- Covington & Burling LLPnorm: covington burling
- Domain
- cov.com
- Industry
- Legal Services
Victim entity
- Name
- Covington & Burling LLPnorm: covington burling
- Domain
- cov.com
- Industry
- Legal Services
- Industry
- Professional Servicesllm
Incident
- Discovered
- Jun 3, 2024
- Materiality determined
- Jun 3, 2024
- Notification sent
- Jun 29, 2024
- Affected individuals
- 2
- Data types
- PII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 28d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 3, 2024→ Filed with AG: Jul 1, 202428d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.