Kirkland & Ellis LLP
ent_019e0db553feb532d82108ae64938cf6
Disclosures
12
State AG · HHS OCR · Leak Site · 9 jurisdictions
Incidents
4
filings grouped by incident
Max affected reported
48,802
nationwide · HHS OCR IL
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Kirkland & Ellis LLP
- Normalized
- kirkland ellis— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300DO60QU86FS5U43
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- kirkland.com
Disclosure history (12)newest first
- 🦀Maryland State AGas reporting2025-11-13
Heavy Construction System Specialists, LLC (HCSS) notified the Maryland Attorney General of a ransomware attack detected on October 18, 2024. The incident affected 2 Maryland residents (employees/former employees), exposing names, addresses, phone numbers, employee IDs, and Social Security Numbers. HCSS engaged cybersecurity experts and law enforcement, and offered 24 months of credit monitoring via Experian IdentityWorks.
- 💎Delaware State AGas reporting2025-01-16
Ascension Health submitted a supplemental notification to the Delaware Department of Justice on February 3, 2025, regarding a prior data security incident. The organization notified approximately 616 Delaware residents via USPS mail after finalizing its data analysis. This filing supplements a previous letter dated December 19, 2024.
- 💎Delaware State AGas reporting2025-01-15
Supplemental breach notification from Ascension Health to the Delaware Department of Justice, filed February 3, 2025. Ascension notified approximately 616 Delaware residents via USPS mail regarding a recent data security incident. The filing supplements a prior letter from December 19, 2024. Specific attack vectors and data types are not detailed in this correspondence.
- 🐻California State AGas victim2024-06-12
Kirkland & Ellis LLP notified individuals of a data breach resulting from a cybersecurity issue in Progress Software's MOVEit Transfer solution. Between May 27 and May 31, 2023, an unauthorized third party accessed files transferred via the tool. Affected data included names, contact info, SSNs, financial account details, health info, credentials, and employment data. The firm engaged cybersecurity experts, notified law enforcement, and offered 24 months of credit monitoring.
- 🦞Maine State AGas victim2024-06-12
Kirkland & Ellis LLP reported a data breach affecting 155 Maine residents, which occurred between May 27, 2023, and May 31, 2023. The breach was discovered on January 23, 2024, and consumers were notified on May 28, 2024. The firm offered 24 months of identity protection and credit monitoring services through Experian. The specific details of the breach and the types of information compromised were not specified in the notification.
- 🦬Montana State AGas victim2024-06-12
Kirkland & Ellis LLP reported a data breach to the Montana Attorney General. The breach was reported on 2024-06-12. The breach occurred from 5/27/2023 to 5/31/2023. 56 Montana residents were affected.
- 🌲Washington State AGas victim2024-06-12
Kirkland & Ellis LLP, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-05-31 and filed notice on 2024-06-12. 810 Washington residents were affected. 378 days elapsed between awareness and notification. 4 days to identify the breach. 0 days to contain the breach.
- 🍁Vermont State AGas victim2024-05-28
Kirkland & Ellis LLP notified consumers of a data breach stemming from a vulnerability in Progress Software's MOVEit Transfer solution. The incident occurred between May 27-31, 2023, affecting files containing PII, government IDs, financial data, health info, and credentials. The firm engaged forensic experts, notified law enforcement, and offered 24 months of credit monitoring.
- ILHHS OCRas victim2024-02-29
Kirkland & Ellis LLP reported to HHS on 2024-02-29 a Hacking/IT Incident affecting 48,802 individuals. Breached information located on Network Server. The business associate exposed PHI including names, SSNs, driver's license numbers, addresses, DOBs, financial/claims info, diagnoses, lab results, and medications. The BA notified HHS, individuals, and media, provided substitute notice, complimentary credit monitoring, and implemented additional safeguards.
- 🐻California State AGas reporting2023-12-15
Riverside County Office of Education notified parents of a data breach involving student information. The incident resulted from a global cybersecurity issue with Progress Software's MOVEit Transfer solution, where unauthorized actors exploited a previously unknown vulnerability. Between May 27 and May 31, 2023, an unauthorized third party obtained files containing student names, academic records, behavior information, enrollment data, special education details, disability codes, dates of birth, and demographic information. No Social Security numbers or financial data were involved. The district engaged cybersecurity experts, secured its MOVEit repository, reported to law enforcement, and offered one year of identity monitoring services to affected families.
- GLOBALLeak Siteas victim2023-06-29
- GLOBALLeak Siteas victim2023-06-29
Home - Kirkland & Ellis LLP