GOODWIN PROCTER LLP
ent_019dea47ac1abc5dc9e5eecccaab4822
Disclosures
25+
State AG · 8 jurisdictions
Multi-filing incidents
9
incidents joining 2+ filings here
Max affected reported
269,773
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- GOODWIN PROCTER LLP
- Normalized
- goodwin procter— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300BRIC6IPNBH9S16
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- goodwinlaw.com
Disclosure history (newest 25)newest first
- Texas State AGas victim2026-07-31
Goodwin Procter LLP based in Washington, District of Columbia, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-04-16 and reported on 2026-07-31. 1,550 Texas residents were affected. 13,805 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Other. Consumers were notified via U.S. Mail.
- New Hampshire State AGas victim2026-06-22
Goodwin Procter LLP experienced a cybersecurity incident on April 16, 2026, when an unauthorized actor compromised a single user account via social engineering. The actor accessed the firm's environment for a limited time and obtained personal information of one New Hampshire resident, including name, address, Social Security number, and financial account details. Goodwin disabled the account, engaged third-party experts, and notified law enforcement. The firm is offering two years of credit monitoring to affected individuals.
- New Hampshire State AGas reporting2026-06-15
Easterly Government Properties, Inc. notified the New Hampshire Attorney General of a third-party data security incident involving its vendor, Ernst and Young LLP (EY). On May 21, 2026, Easterly learned that an unauthorized actor compromised EY’s Jira Service Management platform, resulting in the unauthorized acquisition of personal information for one New Hampshire resident. The affected data included name, physical mailing address, Social Security number, taxable income, and footnote data. Easterly notified the individual on June 8, 2026, and offered 24 months of complimentary credit monitoring and identity restoration services through Epiq. The incident is classified as a supply-chain compromise.
- Indiana State AGas victim2026-06-11
Goodwin Procter LLP reported a data breach to the Indiana Attorney General. The breach occurred on 2026-04-16 and was reported on 2026-06-11. 2 Indiana residents were affected. 31,727 individuals affected in total.
- Massachusetts State AGas victim2026-06-11
Goodwin Procter LLP, a law firm, notified Massachusetts residents of a cybersecurity incident affecting client personal information, including names, Social Security numbers, credit/debit card numbers, and loan account numbers. The firm disabled the affected user account, engaged third-party experts, and notified law enforcement. No evidence of continued unauthorized access was found. The firm is offering two years of complimentary credit and identity monitoring through Equifax.
- Nebraska State AGas victim2026-06-11
Goodwin Procter LLP, a law firm, notified affected individuals of a cybersecurity incident on June 8, 2026. On April 16, 2026, a single user account was compromised via social engineering (phishing). The unauthorized actor accessed client data, including names, Social Security numbers, and credit/debit card numbers. Goodwin disabled the account, engaged third-party experts, and notified law enforcement. No evidence of continued access was found. Two years of credit monitoring via Equifax was offered.
- New Hampshire State AGas reporting2026-05-01
DocketWise, a case management platform for immigration attorneys, issued a supplemental notice to the New Hampshire Attorney General regarding a data security incident. In October 2025, unauthorized actors used valid credentials to access a third-party partner instance, cloning repositories containing customer data. The incident affected 11 New Hampshire residents, exposing names, addresses, SSNs, and government IDs. DocketWise engaged forensic experts, notified the FBI, and provided 24 months of credit monitoring.
- Washington State AGas reporting2026-04-03
DocketWise notified Washington AG of a data security incident in October 2025 involving unauthorized access via valid credentials to third-party partner repositories. The incident affected 689 Washington residents, exposing names, SSNs, DOBs, government IDs, and medical information. DocketWise engaged forensic experts, notified the FBI, and offered 24 months of credit monitoring.
- New Hampshire State AGas reporting2026-04-03
DocketWise, a case management platform for immigration attorneys, notified the New Hampshire Attorney General of a data security incident in October 2025. Unauthorized actors used valid credentials to access a third-party partner instance and clone repositories containing customer data. The incident affected 15 New Hampshire residents, exposing names, addresses, SSNs, and government IDs. DocketWise engaged forensic experts, notified the FBI, and provided 24 months of credit monitoring.
- Maine State AGas reporting2026-04-03
DocketWise, a legal-tech provider, notified regulators of a data security incident where an unauthorized actor used valid credentials to clone third-party partner repositories. The incident affected the personal information (name, address, SSN, government ID) of approximately 116,666 individuals, including 13 Maine residents. DocketWise engaged forensic experts, notified the FBI, and is offering 24 months of credit monitoring.
- Nebraska State AGas reporting2026-04-03
DocketWise, an immigration case management platform, notified the Nebraska Attorney General on April 3, 2026, of a data security incident discovered in October 2025. An unauthorized actor used valid credentials to access a third-party partner instance, cloning repositories containing law firm customer data. The incident affected 94 Nebraska residents, exposing names, addresses, SSNs, and driver's license numbers. DocketWise engaged forensic experts, notified the FBI, and provided 24 months of credit monitoring to affected individuals.
- Vermont State AGas reporting2026-04-03
DocketWise notified the Vermont AG of a data security incident in October 2025 where unauthorized actors used valid credentials to clone third-party partner repositories. The incident affected 34 Vermont residents, exposing names, addresses, SSNs, and government IDs. DocketWise engaged forensic experts, notified the FBI, and offered 24 months of credit monitoring.
- New Hampshire State AGas reporting2025-12-22
OutdoorSmart! Inc. notified the NH Attorney General of a data event affecting 31 NH residents. Unauthorized code on the Campfire Collective website captured payment card info (names, card numbers, CVC) between Feb 15, 2024, and Nov 4, 2025. The code was removed Nov 4, 2025. Notices were sent Dec 19, 2025, offering 24 months of credit monitoring.
- Nebraska State AGas reporting2025-12-19
OutdoorSmart! Inc. notified the Nebraska AG of a data event involving unauthorized code on the Campfire Collective website capturing payment card info. The incident occurred between Feb 15, 2024, and Nov 4, 2025, affecting 2 Nebraska residents. OutdoorSmart removed the code, engaged third-party specialists, and provided 24 months of credit monitoring.
- Washington State AGas reporting2025-12-19
OutdoorSmart! Inc. notified Washington AG of a data event affecting 652 residents. Unauthorized code capturing payment card info was present on the Campfire Collective website from Feb 15, 2024 to Nov 4, 2025. Discovered Nov 3, 2025. Notices sent Dec 19, 2025. Remediation included removing code, engaging specialists, and offering 24 months credit monitoring.
- Washington State AGas reporting2025-11-26
Marquis Software Solutions, Inc. reported a ransomware attack on its network in Washington state. Unauthorized access occurred via a SonicWall firewall on August 14, 2025, leading to data encryption and exfiltration. Affected data included names, SSNs, and financial account info for Washington residents. Notifications began November 26, 2025.
- New Hampshire State AGas reporting2025-10-10
Cardiovascular Medicine Associates (MyCardiologist) notified the NH AG of a data event affecting 1 NH resident. Unauthorized access to the email environment occurred May 30, 2025, discovered June 12, 2025. Data included names, addresses, clinical info, DOB, Medicare numbers. Contained and remediated; 24-month credit monitoring offered.
- New Hampshire State AGas victim2025-07-07
Goodwin Procter LLP notified NH AG of a cybersecurity incident resulting from a third-party provider (Commvault) breach. Unauthorized access occurred April 29-May 1, 2025, using compromised credentials to access select email accounts. Personal information (name, SSN, DOB, passport) of 4 NH residents was exposed. Goodwin contained the incident, engaged forensic experts, notified law enforcement, and is offering 24 months of credit monitoring.
- Vermont State AGas victim2025-07-06
Goodwin Procter LLP notified Vermont AG of a cybersecurity incident affecting client personal information (names, SSNs, DOBs, passports, addresses). The intrusion occurred on April 29, 2025, via a third-party technology provider, Commvault, and was contained on May 2, 2025. Goodwin updated credentials, engaged forensic experts, notified law enforcement, and offered 24 months of credit monitoring. No evidence of continued access was found.
- Maine State AGas victim2025-07-02
Goodwin Procter LLP reported a cybersecurity incident affecting 363 individuals, including 2 Maine residents. The breach occurred April 29-May 1, 2025, stemming from a third-party technology provider (Commvault). Unauthorized access to a small number of email accounts was discovered on May 2, 2025. Affected data included personal identifiers. Goodwin contained the breach, updated credentials, notified law enforcement, and provided 24 months of Equifax credit monitoring.
- Indiana State AGas victim2025-07-02
Goodwin Procter LLP reported a data breach to the Indiana Attorney General. The breach occurred on 2025-04-29 and was reported on 2025-07-02. 35 Indiana residents were affected. 363 individuals affected in total.
- Massachusetts State AGas victim2025-07-02
Goodwin Procter LLP reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-07-02. 138 Massachusetts residents were affected.
- Nebraska State AGas victim2025-07-02
Goodwin Procter LLP notified Nebraska AG of a cybersecurity incident involving a third-party technology provider, Commvault. The intrusion affected a small number of firm email accounts starting April 29, 2025, and was discovered on May 2, 2025. Goodwin contained the breach, updated credentials, engaged third-party experts, and notified law enforcement. Affected individuals received 24 months of credit monitoring via Equifax. No evidence of continued threat actor access was found.
- Maine State AGas reporting2024-10-17
Loring, Wolcott & Coolidge, a financial services firm, disclosed a cybersecurity incident where unauthorized access occurred between April 26 and May 12, 2024. The breach involved malware impacting systems and the acquisition of personal data, including SSNs, driver's licenses, and financial account numbers, affecting approximately 8,056 individuals. Notices were sent on October 17, 2024.
- Washington State AGas reporting2023-12-29
Fallon Ambulance Services, a subsidiary of Transformative Healthcare, reported a ransomware incident affecting archived data of approximately 940 Washington residents. Unauthorized access occurred between Feb 17 and Apr 22, 2023, detected on Apr 21, 2023. Impacted data included names, SSNs, medical info, and employment data. Fallon engaged third-party specialists and federal law enforcement, and offered two years of identity protection services.