Breach report · Legal

Law Firm With High-Profile Client List Hit by Ransomware Attack

A ransomware attack on law firm Campbell Conroy & O'Neil exposed client names, driver's license numbers, financial data and login credentials.

Exploit: Ransomware Company: Campbell Conroy & O’Neil, P.C. Industry: Law Firm Sources: bleepingcomputer.com

After suffering from a Ransomware attack in February 2021, Campbell Conroy & O’Neil, a law firm with dozens of high-profile Fortune 500 and Global 500 companies on their client list, recently announced a data breach.

At the time of the Ransomware attack, the firm announced that it was unclear whether bad actors had stolen client data. Further investigations have since determined that client data was indeed stolen. Bad actors were able to take client data including; names, dates of birth, driver’s license numbers, financial account info, passport numbers, medical information, usernames & passwords, and online account login credentials.

The impacts of such a data breach can go beyond direct costs with a lengthy and ongoing investigation, reputational damages and even lead to further incidents with Ransomware and other malicious attacks deployed on those whose data was stolen.

More from the feed

Other incidents we've written up.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.