MORGAN, LEWIS & BOCKIUS LLP
ent_019e615855a505ff8850b1a26c50b673
Disclosures
25+
State AG · 5 jurisdictions
Multi-filing incidents
16
incidents joining 2+ filings here
Max affected reported
19,419
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MORGAN, LEWIS & BOCKIUS LLP
- Normalized
- morgan lewis bockius— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300XA8FMMVYUI7N50
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (newest 25)newest first
- New Hampshire State AGas reporting2025-12-04
University of Pennsylvania notified NH AG of a security incident involving Oracle E-Business Suite. A previously unknown vulnerability allowed unauthorized access to financial application data. 1,588 NH residents affected; data included names, addresses, SSNs, and banking info. Notification began Dec 1, 2025, offering 24 months credit monitoring. No evidence of misuse. Law enforcement notified.
- Iowa State AGas reporting2025-12-01
University of Pennsylvania notified Iowa AG of a security incident involving its third-party Oracle E-Business Suite. A previously unknown vulnerability allowed unauthorized access to data belonging to 752 Iowa residents, exposing names, addresses, SSNs, and banking info. Penn discovered the breach on Nov 11, 2025, notified law enforcement, applied patches, and began notifying residents on Dec 1, 2025, offering 24 months of credit monitoring.
- New Hampshire State AGas reporting2025-08-18
Lands' End, Inc. notified the New Hampshire Attorney General of a data security incident detected on December 6, 2024. An unauthorized third party accessed a small portion of the corporate network and exfiltrated data, including personal information of 8 New Hampshire employees and dependents. Notification letters were mailed on August 13, 2025, offering 24 months of credit monitoring. Customer systems were not impacted.
- Maine State AGas reporting2025-07-28
The Episcopal Church Foundation reported a third-party IT vendor breach occurring Feb 7-17, 2025. Unauthorized access led to acquisition of files containing personal information. 1,475 individuals affected, including 13 Maine residents. ECF severed vendor connection, engaged forensic experts, notified law enforcement, and offered 24 months of TransUnion credit monitoring.
- Maine State AGas reporting2025-05-06
Woods Hole Group experienced a cybersecurity incident on January 13, 2025, discovered on March 4, 2025. Unauthorized access resulted in the acquisition of files containing Social Security numbers, driver's license numbers, bank information, and dates of birth. 174 individuals were affected, including 6 Maine residents. The company engaged external cybersecurity experts, notified law enforcement, and offered 24 months of Experian IdentityWorks to affected individuals.
- New Hampshire State AGas reporting2024-06-11
The Lash Group, LLC notified the NH Attorney General of a data security incident affecting 420 NH residents. Cencora (Lash Group's partner) detected unauthorized exfiltration of PII on Feb 21, 2024. Notifications sent June 7, 2024, offering credit monitoring.
- New Hampshire State AGas reporting2024-06-03
The Lash Group, LLC notified the New Hampshire Attorney General of a data security incident affecting 8,508 NH residents. Data was exfiltrated from Lash Group's systems, which held information via a partnership with Sanofi US Services Inc. The incident was discovered on Feb 21, 2024. Affected data included names, SSNs, and DOBs. Credit monitoring was offered.
- New Hampshire State AGas reporting2024-05-28
Lash Group LLC notified NH AG of a data security incident affecting 5,191 NH residents. Data exfiltrated from Lash Group's systems, which held PII for GSK patients. Lash Group discovered the incident on Feb 21, 2024. Affected data includes names, SSNs, DOBs, and financial info. Credit monitoring offered.
- New Hampshire State AGas reporting2024-05-28
The Lash Group, LLC notified the New Hampshire Attorney General of a data security incident affecting 31 NH residents. Cencora (parent of Lash Group) detected unauthorized exfiltration of personal information (including SSN, DOB, driver's license) on Feb 21, 2024. Notifications sent May 22, 2024, offering 2 years of credit monitoring.
- New Hampshire State AGas reporting2024-05-28
Lash Group, LLC notified the NH Attorney General of a data security incident affecting 164 NH residents. Data was exfiltrated from Lash Group's systems, which held PII for Incyte Corporation patients. Lash Group discovered the incident on Feb 21, 2024, and sent notifications on May 23, 2024. Affected data included names, SSNs, and DOBs. Credit monitoring was offered.
- New Hampshire State AGas reporting2024-05-23
The Lash Group, LLC notified the New Hampshire Attorney General of a data security incident affecting 9 NH residents. Cencora (Lash Group's partner) detected exfiltration on Feb 21, 2024. PII including SSNs and DOBs were involved. Notifications sent May 20, 2024, offering credit monitoring.
- Washington State AGas reporting2024-05-20
The Lash Group, LLC, a partner of Cencora, experienced a data security incident where personal information of 2,060 Washington residents was exfiltrated. The data included names, addresses, dates of birth, health diagnoses, and medications. The incident was discovered on February 21, 2024, and notifications were sent on May 20, 2024. Affected individuals were offered 24 months of credit monitoring.
- New Hampshire State AGas reporting2024-05-20
The Lash Group, LLC notified the New Hampshire Attorney General of a data security incident affecting 11,503 state residents. Personal information, including names and government IDs, was exfiltrated from systems managed for Bristol Myers Squibb. Cencora initially detected unauthorized activity on Feb 21, 2024. Affected individuals received credit monitoring services.
- New Hampshire State AGas reporting2023-12-14
Independent Living Systems, LLC notified the NH AG of a data breach involving Progress Software's MOVEit Transfer. A zero-day vulnerability allowed unauthorized access. One NH resident's PHI and personal info were affected. ILS disabled the tool, engaged experts, notified law enforcement, and offered credit monitoring.
- Maine State AGas reporting2023-12-14
Independent Living Systems, LLC, a healthcare entity based in Florida, reported an external system breach (hacking) occurring on May 31, 2023, discovered on October 27, 2023. The incident affected 19,419 individuals, including 9 Maine residents. Acquired data included names and Social Security Numbers. The entity provided written notification and offered two years of credit monitoring services through TransUnion/Cyberscout.
- New Hampshire State AGas reporting2023-12-07
Pan-American Life Insurance Group notified NH AG of a data incident involving the MOVEit Transfer zero-day vulnerability exploited by an unauthorized third party to exfiltrate personal information (including SSNs and DOBs) of 48 NH residents. Notifications sent Dec 4, 2023, offering 24 months credit monitoring.
- Washington State AGas reporting2023-12-04
Pan-American Life Insurance Group (PALIG) notified the Washington AG of a data security incident involving the MOVEit Transfer vulnerability exploited by an unauthorized third party. The breach affected 616 Washington residents, exposing PII including SSNs, driver's licenses, medical info, and financial data. PALIG patched the vulnerability, engaged forensic experts, notified law enforcement, and offered 24 months of credit monitoring.
- New Hampshire State AGas reporting2023-09-22
Pension Benefit Information, LLC (PBI) notified the NH AG of a breach involving its MOVEit Transfer server, exploited via a zero-day vulnerability in Progress Software's software. Attackers accessed the server on May 29-30, 2023, exfiltrating personal information (names, SSNs, DOBs, etc.) of 80 NH residents. Notifications were mailed on August 31, 2023, offering 24 months of credit monitoring.
- Massachusetts State AGas victim2022-12-29
Morgan, Lewis & Bockius LLP reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-12-29. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas reporting2022-02-03
PUMA North America, Inc. reported an external system breach (hacking) occurring on 12/11/2021, discovered on 01/10/2022. The incident affected 6,632 individuals, including 17 Maine residents. Acquired data included names and Social Security Numbers. PUMA provided written notification and offered two years of credit monitoring and identity protection services through Experian.
- New Hampshire State AGas reporting2021-05-11
Pan-American Life Insurance Group (PALIG) filed a supplemental notice with the New Hampshire Attorney General regarding a data security incident. PALIG confirmed that while personal information (names, addresses, DOBs) was exfiltrated, no NH residents were among those whose more sensitive personal information was taken. The incident involved unauthorized access and data exfiltration.
- New Hampshire State AGas reporting2021-04-07
Cardiva Medical, Inc. notified the New Hampshire Attorney General on April 1, 2021, of a data security incident confirmed on March 23, 2021. The incident involved the exfiltration of personal information from current and former employees, including names, SSNs, bank account details, and driver's license copies. Five New Hampshire residents were identified as affected. Cardiva engaged third-party experts, strengthened system security, and offered two years of credit monitoring. No evidence of fraud or public disclosure was found.
- New Hampshire State AGas reporting2021-03-15
Pan-American Life Insurance Group (PALIG) notified the NH Attorney General of a cybersecurity incident detected on February 19, 2021. A phishing attempt led to malware installation; defenses limited its impact. Exfiltrated data included names, addresses, dates of birth, and potentially sensitive info for a small subset of ~51 NH policyholders. PALIG took systems offline, engaged forensic experts, and offered credit monitoring to affected individuals.
- Washington State AGas reporting2020-07-07
Freddie Mac notified Washington AG of a ransomware attack on a third-party vendor on May 20, 2020. The attack affected loan application data (SSN, DOB, bank info) of 596 Washington residents. No evidence of data access was found. Freddie Mac sent notifications and offered 2 years of credit monitoring.
- New Hampshire State AGas reporting2018-02-02
Eastern Salt Company, Inc. notified the NH AG of a potential security breach affecting 14 NH residents. Unauthorized access to employee personal info (names, DOB, SSNs) was discovered Jan 18, 2018 via abnormal mobile phone activity. Investigation ongoing. Credit monitoring offered.