GOODWIN PROCTER LLP
ent_019dea47ac1abc5dc9e5eecccaab4822
Disclosures
17
State AG · 7 jurisdictions
Incidents
6
filings grouped by incident
Max affected reported
31,727
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- GOODWIN PROCTER LLP
- Normalized
- goodwin procter— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300BRIC6IPNBH9S16
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- goodwinlaw.com
Disclosure history (17)newest first
- ⭐Texas State AGas victim2026-07-31
Goodwin Procter LLP based in Washington, District of Columbia, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-04-16 and reported on 2026-07-31. 1,550 Texas residents were affected. 13,805 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Other. Consumers were notified via U.S. Mail.
- ⛰️New Hampshire State AGas victim2026-06-22
Goodwin Procter LLP reported a cybersecurity incident to the New Hampshire Attorney General on June 22, 2026. On April 16, 2026, a single user account was compromised via social engineering (phishing). The attacker accessed the network for a limited period, obtaining personal information of one New Hampshire resident, including name, address, SSN, and financial account/credit card numbers. Goodwin disabled the account, engaged third-party experts, notified law enforcement, and offered two years of credit monitoring. The incident is contained.
- ⛰️New Hampshire State AGas reporting2026-06-15
Easterly Government Properties, Inc. notified the New Hampshire Attorney General of a third-party data security incident involving its vendor, Ernst and Young LLP (EY). On May 21, 2026, Easterly learned that an unauthorized actor compromised EY’s Jira Service Management platform, resulting in the unauthorized acquisition of personal information for one New Hampshire resident. The affected data included name, physical mailing address, Social Security number, taxable income, and footnote data. Easterly notified the individual on June 8, 2026, and offered 24 months of complimentary credit monitoring and identity restoration services through Epiq. The incident is classified as a supply-chain compromise.
- 🏎️Indiana State AGas victim2026-06-11
Goodwin Procter LLP reported a data breach to the Indiana Attorney General. The breach occurred on 2026-04-16 and was reported on 2026-06-11. 2 Indiana residents were affected. 31,727 individuals affected in total.
- 🏛️Massachusetts State AGas victim2026-06-01
Goodwin Procter LLP, a law firm, notified Massachusetts residents of a cybersecurity incident affecting client personal information, including names, Social Security numbers, credit/debit card numbers, and loan account numbers. The firm disabled the affected user account, engaged third-party experts, and notified law enforcement. No evidence of continued unauthorized access was found. The firm is offering two years of complimentary credit and identity monitoring through Equifax.
- ⛰️New Hampshire State AGas reporting2026-05-01
DocketWise, a case management platform for immigration attorneys, issued a supplemental notice to the New Hampshire Attorney General regarding a data security incident. In October 2025, unauthorized actors used valid credentials to access a third-party partner instance, cloning repositories containing customer data. The incident affected 11 New Hampshire residents, exposing names, addresses, SSNs, and government IDs. DocketWise engaged forensic experts, notified the FBI, and provided 24 months of credit monitoring.
- ⛰️New Hampshire State AGas reporting2026-04-03
DocketWise, a case management platform for immigration attorneys, notified the New Hampshire Attorney General of a data security incident in October 2025. Unauthorized actors used valid credentials to access a third-party partner instance and clone repositories containing customer data. The incident affected 15 New Hampshire residents, exposing names, addresses, SSNs, and government IDs. DocketWise engaged forensic experts, notified the FBI, and provided 24 months of credit monitoring.
- 🍁Vermont State AGas reporting2026-04-03
DocketWise notified the Vermont AG of a data security incident in October 2025 where unauthorized actors used valid credentials to clone third-party partner repositories. The incident affected 34 Vermont residents, exposing names, addresses, SSNs, and government IDs. DocketWise engaged forensic experts, notified the FBI, and offered 24 months of credit monitoring.
- ⛰️New Hampshire State AGas reporting2025-12-22
OutdoorSmart! Inc. notified the NH Attorney General of a data event affecting 31 NH residents. Unauthorized code on the Campfire Collective website captured payment card info (names, card numbers, CVC) between Feb 15, 2024, and Nov 4, 2025. The code was removed Nov 4, 2025. Notices were sent Dec 19, 2025, offering 24 months of credit monitoring.
- ⛰️New Hampshire State AGas reporting2025-10-10
Cardiovascular Medicine Associates (MyCardiologist) notified the NH AG of a data event affecting 1 NH resident. Unauthorized access to the email environment occurred May 30, 2025, discovered June 12, 2025. Data included names, addresses, clinical info, DOB, Medicare numbers. Contained and remediated; 24-month credit monitoring offered.
- ⛰️New Hampshire State AGas victim2025-07-07
Goodwin Procter LLP notified NH AG of a cybersecurity incident resulting from a third-party provider (Commvault) breach. Unauthorized access occurred April 29-May 1, 2025, using compromised credentials to access select email accounts. Personal information (name, SSN, DOB, passport) of 4 NH residents was exposed. Goodwin contained the incident, engaged forensic experts, notified law enforcement, and is offering 24 months of credit monitoring.
- 🍁Vermont State AGas victim2025-07-06
Goodwin Procter LLP notified Vermont AG of a cybersecurity incident affecting client personal information (names, SSNs, DOBs, passports, addresses). The intrusion occurred on April 29, 2025, via a third-party technology provider, Commvault, and was contained on May 2, 2025. Goodwin updated credentials, engaged forensic experts, notified law enforcement, and offered 24 months of credit monitoring. No evidence of continued access was found.
- 🦞Maine State AGas victim2025-07-02
Goodwin Procter LLP, a law firm, experienced an unauthorized intrusion into a small number of firm email accounts between April 29 and May 1, 2025, discovered on May 2, 2025. The intrusion was attributed to a compromise involving third-party technology provider Commvault. A total of 363 individuals were affected, including 2 Maine residents. Affected credentials were updated, law enforcement was notified, and 24-month Equifax credit monitoring was offered.
- 🏎️Indiana State AGas victim2025-07-02
Goodwin Procter LLP reported a data breach to the Indiana Attorney General. The breach occurred on 2025-04-29 and was reported on 2025-07-02. 35 Indiana residents were affected. 363 individuals affected in total.
- ⛰️New Hampshire State AGas reporting2023-10-23
Bank of Canton notified the New Hampshire Attorney General of a data security incident involving its third-party service provider's use of Progress Software's MOVEit application. The provider suffered a cybersecurity incident on or around May 27, 2023, exploiting a previously unknown vulnerability. Bank of Canton was notified on August 3, 2023. Approximately 41 New Hampshire residents were affected. Personal information related to deposit accounts was potentially obtained. No evidence of misuse was found. Notifications were mailed on October 20, 2023, offering credit monitoring.
- 🦞Maine State AGas reporting2023-10-23
Bank of Canton reported a data breach occurring on May 27, 2023, discovered on September 22, 2023. The incident involved the exploitation of a vulnerability on an FTP platform used by a third-party service provider. Approximately 10,070 individuals were affected, including 31 Maine residents. The breach compromised names and Social Security Numbers. The bank provided written notification and offered 24 months of identity theft protection services via Kroll, Inc.
- 🦬Montana State AGas victim2021-04-09
Goodwin Proctor LLP reported a data breach to the Montana Attorney General. The breach was reported on 2021-04-09. The breach occurred on 1/20/2021. 9 Montana residents were affected.