Orrick, Herrington & Sutcliffe LLP
ent_019dee47ddee48c74f0c591adea20441
Disclosures
25+
Leak Site · State AG · HHS OCR · 6 jurisdictions
Incidents
5
filings grouped by incident
Max affected reported
637,620
as filed · State AG ME
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Orrick, Herrington & Sutcliffe LLP
- Normalized
- orrick herrington sutcliffe— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300WECABRQKMIDJ49
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- orrick.com
Disclosure history (newest 25)newest first
- GLOBALLeak Siteas victim2026-02-23
Founded in 1963 and headquartered in San Francisco, California, Orrick, Herrington & Sutcliffe is a co...
- ⛰️New Hampshire State AGas reporting2025-12-15
Event Rental Systems (operated by Fullsteam Software Holdings LLC) disclosed a security event where unauthorized code was inserted into customer website modules between October 2024 and October 2025. The code scraped payment card data (number, CVV, expiration) and customer contact info. 6 New Hampshire residents were affected. The company engaged forensic investigators, notified law enforcement and card brands, removed the code, and offered 12 months of credit monitoring via Experian. Notifications began December 15, 2025.
- ⛰️New Hampshire State AGas reporting2025-11-06
Pillsbury Winthrop Shaw Pitman LLP notified the New Hampshire Attorney General of a security event involving sophisticated social engineering. An unauthorized actor convinced a user to download firm documents, affecting the financial account information of approximately 4 New Hampshire residents. The firm engaged forensic investigators, notified law enforcement, and is offering 24 months of credit monitoring via Equifax. Notifications began November 6, 2025.
- ⛰️New Hampshire State AGas reporting2025-09-05
Toast, Inc. notified New Hampshire authorities of a security event involving suspicious login activity on its Payroll application. Unauthorized actors accessed employee profiles containing Social Security numbers and basic PII between June 30 and July 17, 2025. Approximately one New Hampshire resident was affected. Toast reset passwords, engaged forensic investigators, notified law enforcement, and offered identity monitoring services.
- 🦞Maine State AGas victim2024-01-24
Orrick, Herrington & Sutcliffe LLP reported an external system breach that occurred on February 28, 2023, and was discovered on March 13, 2023. The breach compromised the names and Social Security numbers of 637,620 individuals. The firm began notifying affected individuals on September 14, 2023, and offered two years of identity monitoring services through Kroll.
- ⛰️New Hampshire State AGas victim2024-01-05
Orrick, Herrington & Sutcliffe LLP notified the New Hampshire Attorney General of a cybersecurity incident detected in March 2023. The breach compromised the personal and protected health information of 637,620 individuals, including vision plan members. The firm engaged forensic investigators, notified law enforcement, and offered two years of complimentary credit monitoring. A class action settlement of $8 million was approved to resolve claims regarding the breach.
- 🐻California State AGas reporting2023-12-28
Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to its network between February 28 and March 13, 2023. The attacker obtained files containing personal information, including data related to MultiPlan, Inc. clients. Orrick detected the access on March 13, 2023, blocked it, and engaged forensic experts. Identity monitoring services are being offered to affected individuals.
- 🐻California State AGas victim2023-11-09
Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to a portion of its network on March 10, 2023. The breach was detected on March 13, 2023. Files containing personal information of plan participants, including health insurance data, were accessed. Orrick engaged cybersecurity experts, notified law enforcement, and is offering two years of identity monitoring to affected individuals.
- ⛰️New Hampshire State AGas victim2023-09-08
State of New Hampshire Attorney General's office received a notification regarding a cybersecurity incident involving Orrick, Herrington & Sutcliffe, LLP. The filing date is September 8, 2023. The provided source document contains no extractable narrative text regarding the nature of the breach, affected data, or individuals involved.
- 🐻California State AGas victim2023-08-21
Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to a portion of its network on March 10, 2023. The breach was detected on March 13, 2023. The incident involved personal information of plan participants, including health insurance data (PHI), stored in connection with Orrick's representation of MultiPlan, Inc. Orrick blocked access, engaged forensic experts, notified law enforcement, and is offering two years of identity monitoring.
- 🦫Oregon State AGas victim2023-08-18
Orrick, Herrington & Sutcliffe LLP reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-18. The breach occurred during 2/28/2023 - 3/13/2023. The breach was discovered on 3/13/2023. 461,100 individuals were affected. Notice was sent on 6/30/20237/20/20238/18/2023.
- 🐻California State AGas victim2023-08-18
Orrick, Herrington & Sutcliffe LLP notified the California Attorney General of a data breach occurring on February 28, 2023. The firm offered two years of complimentary identity monitoring through Kroll to affected individuals. The specific nature of the breach and the types of data compromised are not detailed in the provided notice sample, which contains redacted fields.
- 🦞Maine State AGas victim2023-08-18
Law firm Orrick, Herrington & Sutcliffe LLP reported a data breach impacting 461,100 individuals, including 221 Maine residents. The breach occurred on February 28, 2023, and was discovered on March 13, 2023. The incident was categorized as an external system breach (hacking), where threat actors acquired names combined with driver's license or non-driver identification card numbers. The firm provided written notification to affected individuals on July 20, 2023, and August 18, 2023, and offered two years of Kroll identity monitoring services.
- 🐻California State AGas victim2023-08-14
Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to a portion of its network on March 10, 2023. The breach was detected on March 13, 2023. Files containing personal information of plan participants, including health insurance data, were accessed. Orrick is a downstream service provider for MultiPlan, Inc. The firm engaged cybersecurity experts, notified law enforcement, and is offering two years of identity monitoring through Kroll.
- 🐻California State AGas victim2023-07-31
Orrick, Herrington & Sutcliffe LLP reported a data breach to the California Attorney General. The incident occurred on March 7, 2023. The firm offered identity monitoring services to affected individuals. The specific nature of the breach and data types are not detailed in the provided summary page, though PII is implied by the offer of identity monitoring.
- ⛰️New Hampshire State AGas victim2023-07-25
State AG breach notification filed by Orrick, Herrington and Sutcliff, LLP in New Hampshire on July 25, 2023. The attached consumer notification letter text is empty or unreadable in the provided source, preventing extraction of incident details, dates, or affected data types.
- 🦞Maine State AGas victim2023-07-20
Orrick, Herrington & Sutcliffe LLP reported an external system breach (hacking) occurring on 02/28/2023 and discovered on 03/13/2023. The incident affected 152,818 individuals, including 1 Maine resident. Personal information acquired included names and Social Security Numbers. The firm provided written notification and offered 24 months of complimentary identity monitoring services through Kroll.
- 🦞Maine State AGas victim2023-07-20
Legal services firm Orrick, Herrington & Sutcliffe LLP reported a data breach affecting 152,818 individuals, including 27 Maine residents. The breach, described as an external system breach (hacking), occurred on March 7, 2023, and was discovered on March 13, 2023. The compromised information includes names and Social Security numbers. The firm began notifying affected individuals on July 21, 2023, and offered two years of identity monitoring services through Kroll.
- 🐻California State AGas victim2023-07-20
Orrick, Herrington & Sutcliffe LLP notified the California AG of a security event on March 7, 2023, affecting individuals enrolled in a vision benefits plan for which Orrick served as legal counsel. Affected data included name, address, date of birth, and Social Security numbers. Orrick offered free identity monitoring services.
- 🐻California State AGas reporting2023-07-20
Orrick, Herrington & Sutcliffe LLP experienced a security event where an unauthorized third party gained remote access to a portion of its network between February 28 and March 13, 2023. The intrusion was detected on March 13, 2023. The attacker obtained files containing personal and protected health information (PHI) of clients, including Delta Dental of California members. Social Security numbers and financial account information were not involved. Orrick engaged forensic experts, notified law enforcement, and is offering two years of identity monitoring to affected individuals.
- ⛰️New Hampshire State AGas victim2023-07-03
Orrick, Herrington & Sutcliffe, LLP notified the NH Attorney General of a security incident detected on March 13, 2023. An unauthorized third party gained remote access to a file share, obtaining personal information of clients' customers between Feb 28 and Mar 13, 2023. 770 NH residents affected. Orrick engaged forensic experts, notified law enforcement, and offered 2 years of credit monitoring via Kroll.
- 🦫Oregon State AGas victim2023-06-30
Orrick, Herrington & Sutcliffe LLP reported a data breach to the Oregon Attorney General. The breach was reported on 2023-06-30. The breach occurred during 3/7/2023 - 3/7/2023. The breach was discovered on 3/13/2023. 118,965 individuals were affected. Notice was sent on 6/30/2023.
- 🌲Washington State AGas victim2023-06-30
Orrick, Herrington & Sutcliffe LLP, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-03-13 and filed notice on 2023-06-30. 6,376 Washington residents were affected. 109 days elapsed between awareness and notification. 6 days to identify the breach. 0 days to contain the breach.
- CALIFORNIAHHS OCRas victim2023-06-30
Orrick, Herrington & Sutcliffe LLP reported to HHS on 2023-06-30 a Hacking/IT Incident affecting 342,176 individuals. Breached information located on Network Server. The business associate experienced a cyber-attack compromising PHI including names, diagnoses, SSNs, and insurance info. Response included credit monitoring and enhanced safeguards.
- 🐻California State AGas victim2023-06-30
Orrick, Herrington & Sutcliffe LLP notified the California AG of a security event impacting data obtained during its representation of a vision benefits plan manager. The incident, dated March 7, 2023, exposed names, addresses, dates of birth, and Social Security numbers. The firm offered free identity monitoring services to affected individuals.