KIRKLAND & ELLIS LLP
ent_019e0db553feb532d82108ae64938cf6
Disclosures
15
State AG · HHS OCR · Leak Site · 11 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
5,466,931
nationwide · State AG NH
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- KIRKLAND & ELLIS LLP
- Normalized
- kirkland ellis— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300DO60QU86FS5U43
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- kirkland.com
Disclosure history (15)newest first
- Maryland State AGas reporting2025-11-13
Heavy Construction System Specialists, LLC (HCSS) notified the Maryland Attorney General of a ransomware attack detected on October 18, 2024. The incident affected 2 Maryland residents (employees/former employees), exposing names, addresses, phone numbers, employee IDs, and Social Security Numbers. HCSS engaged cybersecurity experts and law enforcement, and offered 24 months of credit monitoring via Experian IdentityWorks.
- Rhode Island State AGas reporting2025-02-20
Medusind, Inc., a revenue cycle management company, notified the Rhode Island Attorney General of a cybersecurity incident discovered on December 29, 2023. Suspicious activity led to the offline of systems and an FBI-reported investigation. Files containing patient PII (SSN, medical records, payment info) were copied. Medusind notified 81 RI residents starting January 7, 2025, offering 24 months of identity monitoring.
- New Hampshire State AGas reporting2025-02-07
Supplemental notice from Ascension Health to the New Hampshire Attorney General regarding a data security incident. Ascension notified 645 NH residents and approximately 5.47 million individuals nationwide. The filing supplements a prior letter from December 19, 2024. Incident details and data types are not specified in this correspondence.
- New Hampshire State AGas victim2024-06-17
Kirkland & Ellis LLP notified the NH AG of a breach involving its third-party provider Progress Software's MOVEit Transfer tool. Unauthorized access occurred May 27-31, 2023. The firm identified 12 affected NH residents, whose personal info (names, addresses) was accessed. Kirkland engaged forensic experts, notified law enforcement, and is offering 24 months of credit monitoring.
- California State AGas victim2024-06-12
Kirkland & Ellis LLP notified individuals of a data breach resulting from a cybersecurity issue in Progress Software's MOVEit Transfer solution. Between May 27 and May 31, 2023, an unauthorized third party accessed files transferred via the tool. Affected data included names, contact info, SSNs, financial account details, health info, credentials, and employment data. The firm engaged cybersecurity experts, notified law enforcement, and offered 24 months of credit monitoring.
- Maine State AGas victim2024-06-12
Kirkland & Ellis LLP reported a data breach involving its third-party vendor, Progress Software's MOVEit Transfer solution. The incident occurred between May 27-31, 2023, and was discovered on January 23, 2024. Approximately 11,156 individuals were affected, including 155 Maine residents. Compromised data included names, contact info, government IDs, financial accounts, health info, credentials, and employment data. The firm engaged forensic experts, notified law enforcement, and offered 24 months of credit monitoring.
- Montana State AGas victim2024-06-12
Kirkland & Ellis LLP notified Montana residents of a data breach involving its third-party file transfer provider, Progress Software's MOVEit Transfer solution. Unauthorized access occurred between May 27-31, 2023. Affected data included names, SSNs, DOBs, financial accounts, health info, and credentials. The firm engaged forensic experts, notified law enforcement, and offered 24 months of credit monitoring.
- Washington State AGas victim2024-06-12
Kirkland & Ellis LLP reported a data breach involving its third-party vendor Progress Software's MOVEit Transfer solution. Unauthorized access occurred between May 27-31, 2023, affecting personal information including names, SSNs, financial accounts, and health data. 810 Washington residents were notified. The firm engaged forensic experts, notified law enforcement, and offered 24 months of credit monitoring.
- Illinois State AGas victim2024-06-01
KIRKLAND & ELLIS LLP filed a data-breach notice with the Illinois Attorney General in June 2024 (case 24-06-024). The register records the breach as discovered on May 27, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Vermont State AGas victim2024-05-28
Kirkland & Ellis LLP notified consumers of a data breach stemming from a vulnerability in Progress Software's MOVEit Transfer solution. The incident occurred between May 27-31, 2023, affecting files containing PII, government IDs, financial data, health info, and credentials. The firm engaged forensic experts, notified law enforcement, and offered 24 months of credit monitoring.
- ILLINOISHHS OCRas victim2024-02-29
Kirkland & Ellis LLP reported to HHS on 2024-02-29 a Hacking/IT Incident affecting 48,802 individuals. Breached information located on Network Server. The business associate exposed PHI including names, SSNs, driver's license numbers, addresses, DOBs, financial/claims info, diagnoses, lab results, and medications. The BA notified HHS, individuals, and media, provided substitute notice, complimentary credit monitoring, and implemented additional safeguards.
- Washington State AGas reporting2024-02-26
Federal Way School District notified of MOVEit Transfer vulnerability exploitation by third-party vendor Progress Software. Unauthorized access occurred May 27-31, 2023. 35,274 Washington students affected; data included names, DOB, IDs, and education records. Kirkland & Ellis LLP reported on behalf of the District.
- Massachusetts State AGas victim2023-09-07
Kirkland & Ellis LLP reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-09-07. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- GLOBALLeak Siteas victim2023-06-29
- GLOBALLeak Siteas victim2023-06-29
Home - Kirkland & Ellis LLP
Supply-chain cascadesreviewed and confirmed
- KIRKLAND & ELLIS LLP’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).