Orrick, Herrington & Sutcliffe LLP
ent_019dee47ddee48c74f0c591adea20441
Disclosures
25+
Leak Site · State AG · 9 jurisdictions
Multi-filing incidents
7
incidents joining 2+ filings here
Max affected reported
637,620
nationwide · State AG ME
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Orrick, Herrington & Sutcliffe LLP
- Normalized
- orrick herrington sutcliffe— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300WECABRQKMIDJ49
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- orrick.com
Disclosure history (newest 25)newest first
- GLOBALLeak Siteas victim2026-02-23
Founded in 1963 and headquartered in San Francisco, California, Orrick, Herrington & Sutcliffe is a co...
- New Hampshire State AGas reporting2025-12-15
Event Rental Systems (operated by Fullsteam Software Holdings LLC) disclosed a security event where unauthorized code was inserted into customer website modules between October 2024 and October 2025. The code scraped payment card data (number, CVV, expiration) and customer contact info. 6 New Hampshire residents were affected. The company engaged forensic investigators, notified law enforcement and card brands, removed the code, and offered 12 months of credit monitoring via Experian. Notifications began December 15, 2025.
- Iowa State AGas reporting2025-12-09
Prosper Marketplace, Inc. notified the Iowa AG of a security incident discovered on September 1, 2025. Unauthorized actors accessed data of approximately 1,008 Iowa residents between June and August 2025. Compromised data included SSNs, dates of birth, and bank account numbers. Prosper engaged Mandiant, notified law enforcement, and is offering two years of credit monitoring.
- New Hampshire State AGas reporting2025-11-06
Pillsbury Winthrop Shaw Pitman LLP notified the New Hampshire Attorney General of a security event involving sophisticated social engineering. An unauthorized actor convinced a user to download firm documents, affecting the financial account information of approximately 4 New Hampshire residents. The firm engaged forensic investigators, notified law enforcement, and is offering 24 months of credit monitoring via Equifax. Notifications began November 6, 2025.
- Iowa State AGas reporting2025-11-06
Pillsbury Winthrop Shaw Pitman LLP notified the Iowa AG of a security event in late April 2025 involving sophisticated social engineering. An unauthorized actor downloaded firm documents after convincing a user to enable access. Notices began rolling out November 6, 2025. Data types include PII and government IDs. No specific count of affected individuals was provided in this courtesy notice.
- New Hampshire State AGas reporting2025-09-05
Toast, Inc. notified New Hampshire authorities of a security event involving suspicious login activity on its Payroll application. Unauthorized actors accessed employee profiles containing Social Security numbers and basic PII between June 30 and July 17, 2025. Approximately one New Hampshire resident was affected. Toast reset passwords, engaged forensic investigators, notified law enforcement, and offered identity monitoring services.
- Maryland State AGas reporting2025-03-18
Uni-Select notified Maryland AG of a November 2024 security incident affecting one Maryland resident. Unusual activity led to systems going offline. Affected data included name, workplace accident info, and health insurance details. Notification sent Feb 20, 2025, with Equifax credit monitoring offered. Threat actor described as financially motivated and sophisticated.
- Maine State AGas victim2024-01-24
Orrick, Herrington & Sutcliffe LLP reported an external system breach that occurred on February 28, 2023, and was discovered on March 13, 2023. The breach compromised the names and Social Security numbers of 637,620 individuals. The firm began notifying affected individuals on September 14, 2023, and offered two years of identity monitoring services through Kroll.
- New Hampshire State AGas victim2024-01-05
Orrick, Herrington & Sutcliffe LLP filed a supplemental notice with the New Hampshire Attorney General regarding a security incident detected on March 13, 2023. An unauthorized third party gained remote access to a file share containing client files between February 28 and March 13, 2023. The breach affected approximately 406 New Hampshire individuals, exposing personal information. Orrick engaged third-party cybersecurity experts, notified law enforcement, and offered two years of complimentary identity monitoring services.
- California State AGas victim2023-12-28
Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to its network between February 28 and March 13, 2023. The attacker obtained files containing personal information, including data related to MultiPlan, Inc. clients. Orrick detected the access on March 13, 2023, blocked it, and engaged forensic experts. Identity monitoring services are being offered to affected individuals.
- California State AGas victim2023-11-09
Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to a portion of its network on March 10, 2023. The breach was detected on March 13, 2023. Files containing personal information of plan participants, including health insurance data, were accessed. Orrick engaged cybersecurity experts, notified law enforcement, and is offering two years of identity monitoring to affected individuals.
- New Hampshire State AGas reporting2023-09-08
Orrick, Herrington & Sutcliffe, LLP submitted a supplemental notice to the New Hampshire Attorney General regarding a security incident affecting Tufts Associated Health Maintenance Organization, Inc. An unauthorized third party gained remote access to Orrick's network between February 28 and March 13, 2023, exfiltrating files containing personal information of 32 New Hampshire residents. Orrick detected the breach on March 13, engaged forensic experts, notified law enforcement, and began notifying affected individuals on August 31, 2023, offering two years of identity monitoring.
- South Carolina State AGas victim2023-09-07
Orrick, Herrington & Sutcliffe, LLP notified South Carolina residents of a security event where an unauthorized third party gained remote access to client files. Access occurred between Feb 28 and Mar 13, 2023. The firm detected the breach on Mar 13, 2023, engaged forensic experts, notified law enforcement, and offered two years of identity monitoring.
- California State AGas victim2023-08-21
Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to a portion of its network on March 10, 2023. The breach was detected on March 13, 2023. The incident involved personal information of plan participants, including health insurance data (PHI), stored in connection with Orrick's representation of MultiPlan, Inc. Orrick blocked access, engaged forensic experts, notified law enforcement, and is offering two years of identity monitoring.
- New Hampshire State AGas victim2023-08-21
Orrick, Herrington & Sutcliffe, LLP filed a supplemental notice with the NH Attorney General regarding a security incident detected on March 13, 2023. An unauthorized third party gained remote access to a file share containing client personal information between Feb 28 and Mar 13, 2023. 449 NH individuals are affected. Orrick engaged forensic experts, notified law enforcement, and offers 2 years of identity monitoring.
- Oregon State AGas victim2023-08-18
Orrick, Herrington & Sutcliffe LLP reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-18. The breach occurred during 2/28/2023 - 3/13/2023. The breach was discovered on 3/13/2023. 461,100 individuals were affected. Notice was sent on 6/30/20237/20/20238/18/2023.
- California State AGas victim2023-08-18
Orrick, Herrington & Sutcliffe LLP notified the California Attorney General of a data breach occurring on February 28, 2023. The firm offered two years of complimentary identity monitoring through Kroll to affected individuals. The specific nature of the breach and the types of data compromised are not detailed in the provided notice sample, which contains redacted fields.
- Maine State AGas victim2023-08-18
Law firm Orrick, Herrington & Sutcliffe LLP reported a data breach impacting 461,100 individuals, including 221 Maine residents. The breach occurred on February 28, 2023, and was discovered on March 13, 2023. The incident was categorized as an external system breach (hacking), where threat actors acquired names combined with driver's license or non-driver identification card numbers. The firm provided written notification to affected individuals on July 20, 2023, and August 18, 2023, and offered two years of Kroll identity monitoring services.
- California State AGas victim2023-08-14
Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to a portion of its network on March 10, 2023. The breach was detected on March 13, 2023. Files containing personal information of plan participants, including health insurance data, were accessed. Orrick is a downstream service provider for MultiPlan, Inc. The firm engaged cybersecurity experts, notified law enforcement, and is offering two years of identity monitoring through Kroll.
- California State AGas victim2023-07-31
Orrick, Herrington & Sutcliffe LLP reported a data breach to the California Attorney General. The incident occurred on March 7, 2023. The firm offered identity monitoring services to affected individuals. The specific nature of the breach and data types are not detailed in the provided summary page, though PII is implied by the offer of identity monitoring.
- New Hampshire State AGas reporting2023-07-25
Orrick, Herrington & Sutcliffe, LLP filed a supplemental notice on behalf of Delta Dental of California regarding a March 13, 2023 security event. Unauthorized access to a file share occurred between Feb 28 and Mar 13, 2023, exposing PII and PHI of insureds. 137 NH residents notified. Identity monitoring offered.
- Indiana State AGas victim2023-07-20
Orrick, Herrington & Sutcliffe LLP reported a data breach to the Indiana Attorney General. The breach occurred on 2023-02-28 and was reported on 2023-07-20. 15,275 Indiana residents were affected. 506,475 individuals affected in total.
- Maine State AGas victim2023-07-20
Orrick, Herrington & Sutcliffe LLP reported an external system breach (hacking) occurring on 02/28/2023 and discovered on 03/13/2023. The incident affected 152,818 individuals, including 1 Maine resident. Personal information acquired included names and Social Security Numbers. The firm provided written notification and offered 24 months of complimentary identity monitoring services through Kroll.
- Maine State AGas victim2023-07-20
Legal services firm Orrick, Herrington & Sutcliffe LLP reported a data breach affecting 152,818 individuals, including 27 Maine residents. The breach, described as an external system breach (hacking), occurred on March 7, 2023, and was discovered on March 13, 2023. The compromised information includes names and Social Security numbers. The firm began notifying affected individuals on July 21, 2023, and offered two years of identity monitoring services through Kroll.
- California State AGas victim2023-07-20
Orrick, Herrington & Sutcliffe LLP notified the California AG of a security event on March 7, 2023, affecting individuals enrolled in a vision benefits plan for which Orrick served as legal counsel. Affected data included name, address, date of birth, and Social Security numbers. Orrick offered free identity monitoring services.