ROPES & GRAY LLP
ent_019e7672fda1f7b2a126fb89dbc288df
Disclosures
12
State AG · 7 jurisdictions
Multi-filing incidents
6
incidents joining 2+ filings here
Max affected reported
314,107
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- ROPES & GRAY LLP
- Normalized
- ropes gray— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300NY2IA704Z1D452
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (12)newest first
- New Hampshire State AGas reporting2026-07-16
Lifespan Physician Group of Massachusetts, Inc. d/b/a Brown Health Medical Group-MA notified the NH Attorney General of a data security incident at its Hawthorn location. Unauthorized access to a historic file server occurred between December 15-16, 2025, and was discovered on December 16, 2025. The incident potentially impacted the personal information of 1,129 New Hampshire residents. The Practice isolated the server, reset passwords, decommissioned the server, retrained employees, and offered two years of identity restoration services. Law enforcement was notified.
- Maryland State AGas reporting2025-11-13
PowerSchool, a technology service provider for school districts, reported a cybersecurity incident in Maryland affecting approximately 145,783 residents. The incident occurred between December 19 and December 28, 2024, involving unauthorized exfiltration of personal information (names, SSNs, DOBs, limited medical alerts) via a customer support portal. PowerSchool engaged forensic experts and law enforcement, and is offering credit monitoring through Experian.
- New Hampshire State AGas reporting2025-10-22
WCAS Management, L.P. notified the NH Attorney General of a ransomware attack by the Akira group. The incident occurred July 31-Aug 1, 2025, exploiting a SonicWall VPN vulnerability. One NH resident's data (PII, SSN, financial info) was exfiltrated. WCAS isolated systems, engaged forensics, and notified law enforcement. Notifications sent Oct 22, 2025, with 24-month credit monitoring.
- New Hampshire State AGas reporting2025-08-22
The MathWorks, Inc. notified the New Hampshire Attorney General of a ransomware incident discovered on May 18, 2025, affecting approximately 87 state residents. Unauthorized access occurred between April 17 and May 18, 2025, resulting in the encryption of servers and access to employee personal information, including SSNs and financial data. MathWorks engaged forensic experts, law enforcement, and provided 24 months of credit monitoring to affected individuals.
- Rhode Island State AGas reporting2025-01-28
PowerSchool notified the Rhode Island Attorney General of a cybersecurity incident occurring between Dec 19-28, 2024. Unauthorized actors exfiltrated personal information from the PowerSource support portal, affecting ~6,766 RI residents. Data included names, SSNs, DOBs, and medical alerts. PowerSchool engaged forensic experts, reported to law enforcement, and offered two years of credit monitoring via Experian.
- Iowa State AGas reporting2025-01-27
PowerSchool, a technology service provider to school districts, notified the Iowa Attorney General on January 27, 2025, of a cybersecurity incident discovered on December 28, 2024. Unauthorized actors exfiltrated personal information from the PowerSchool Student Information System (SIS) via the PowerSource support portal between December 19 and 28, 2024. Approximately 49,921 Iowa residents (students, former students, and teachers) were affected. Data included names, contact info, SSNs, dates of birth, and limited medical alert information. PowerSchool engaged forensic experts, reported to law enforcement, and offered two years of credit monitoring via Experian.
- Idaho State AGas reporting2025-01-27
PowerSchool notified the Idaho Attorney General on January 27, 2025, of a cybersecurity incident occurring between December 19 and 28, 2024. Unauthorized actors exfiltrated personal information from the PowerSchool Student Information System (SIS) via the PowerSource support portal. Approximately 29,074 Idaho residents (students, former students, and teachers) were affected. Data included names, contact info, SSNs, dates of birth, and limited medical alerts. PowerSchool engaged forensic experts, reported to law enforcement, and offered two years of credit monitoring via Experian.
- Washington State AGas reporting2025-01-27
PowerSchool Group LLC reports a cybersecurity incident where personal information of Washington residents was exfiltrated from its cloud environment via a customer support portal. The incident occurred between Dec 19-28, 2024, and was discovered on Dec 28, 2024. Data types included names, DOBs, SSNs, and medical alerts. 314,107 Washington residents were affected. PowerSchool engaged forensic experts and offered credit monitoring.
- Idaho State AGas reporting2025-01-27
Idaho AG received supplemental notice from PowerSchool regarding a cybersecurity incident occurring between Dec 19-28, 2024. Personal information of state residents (students/teachers) was exfiltrated, including names, DOB, SSN, and limited medical alerts. PowerSchool estimates 84% of Idaho customers are hosted; on-prem customer data is excluded from this notice.
- Massachusetts State AGas victim2020-11-01
Ropes & Gray LLP reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-11-01. 4 Massachusetts residents were affected. The report records the breach type as paper.
- Washington State AGas reporting2020-06-03
Bombas LLC notified Washington AG of a security incident where malicious code on its Shopify e-commerce platform may have scraped customer PII and payment card data between Nov 11, 2016 and Feb 16, 2017. Discovered Dec 26, 2018 via Braintree report. 2,313 WA residents affected. Notifications mailed June 3, 2020.
- New Hampshire State AGas reporting2016-08-08
Green Valley Mountain School notified the NH AG that an employee's email account was compromised via phishing. Unauthorized access occurred between May 24 and July 15, 2016. Personal info (SSN, DOB, bank details) of 6 NH employees may have been accessed. Credentials were reset and credit monitoring offered.