News: 1626777905

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

US legal eagles representing Apple, IBM, and more take 5 months to inform clients of ransomware data breach

(2021/07/20)


Law firm Campbell Conroy & O'Neil has warned of a breach from late February which may have exposed data from the company's lengthy client list of big-name corporations including Apple and IBM.

The breach, which was discovered on 27 February 2021 when a ransomware infection blocked access to selected files on the company's internal systems, has been blamed on an unnamed "unauthorised actor."

At the time of writing, none of the usual suspects had claimed responsibility. For REvil, one of the biggest and most successful ransomware groups, that's no surprise: its websites have been down [1]for a week and counting after a wide-ranging attack on IT management firm [2]Kaseya and its clients.

[3]

While it's not yet known precisely what data was accessed during the breach, the system affected held a treasure trove including "certain individuals' names, dates of birth, driver's license numbers/state identification numbers, financial account information, Social Security numbers, passport numbers, payment card information, medical information, health insurance information, biometric data, and/or online account credentials (i.e. usernames and passwords)," the company [4]confirmed in a statement regarding the attack.

[5]Gung-ho tank gamer spills classified docs in effort to win online argument

[6]Report sheds light on 'cocky' but 'creative' Mespinoza ransomware group

[7]You'll never Guess whose data has been nicked as US fashion firm confirms systems breach

[8]Oi! Our British Airways data breach compo sueball is still going, shouts rival law firm

"Campbell is committed to, and takes very seriously, its responsibility to protect all data entrusted to us," the company continued. "As part of our ongoing commitment to the privacy of personal information in our care, we are reviewing our existing policies and procedures, and are working to implement additional safeguards to further secure our information systems."

The company has also offered those affected a 24-month subscription to credit monitoring, fraud consultation, and identity theft restoration services – but only if they had their Social Security numbers held on the system. For those whose data did not include Social Security numbers, they get nothing bar the company's apologies.

[9]

Founded in 1983, Campbell boasts a laundry list of big clients across a range of industries including Ford, Toyota, Honda, and others in automotive; British Airways, Boeing, Continental Airlines, Gulfstream, and others in aerospace; Monsanto, Corning, Dow Chemical, and others in the chemical industry; Apple, IBM, Toshiba Information Systems, and others in computing; Exxon Mobil and BP-owned Amoco in oil; and others too numerous to mention across consumer products, heavy equipment and industrial machinery, insurance, medical and pharmaceutical, retail, transportation, and more.

In short: the impact of the breach could be felt by a huge number of companies, not just Campbell itself. Depending on what data was exposed, it could spell a repeat of the attack on Grubman Shire Meiselas & Sacks last year, which exposed client data belonging to [10]A-list celebrities .

[11]

Campbell confirmed it had enlisted unnamed "third-party forensic investigators" to investigate the attack, and that it had informed the FBI of the breach. It did not, however, indicate why it had taken five months to alert its clients.

Campbell had not responded to a request for additional comment by the time of publication. ®

Get our [12]Tech Resources



[1] https://www.theregister.com/2021/07/13/revil_ransomware_shuts/

[2] https://www.theregister.com/2021/07/13/kaseya_update/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YPbzJwLO-@Y6etnKJUteTwAAAFE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://campbelltriallawyers.com/campbell-conroy-oneil-provides-notice-of-data-privacy-incident/

[5] https://www.theregister.com/2021/07/19/war_thunder_classified_tank_docs/

[6] https://www.theregister.com/2021/07/15/mespinoza_ransomware_profile/

[7] https://www.theregister.com/2021/07/13/guess_spread_group_data_breaches/

[8] https://www.theregister.com/2021/07/07/british_airways_data_breach_rival_lawsuit/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPbzJwLO-@Y6etnKJUteTwAAAFE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2020/05/12/papa_dont_breach/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPbzJwLO-@Y6etnKJUteTwAAAFE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



"Campbell is committed to, and takes very seriously, its responsibility . ."

Pascal Monett

Yes. Of course. The usual bullshit.

You're committed to, of course. You take very seriously, obviously.

And you took five fucking months to reveal the problem.

That is a brilliant demonstration of your actual commitment.

Five months, during which your responsability to protect data left your customers exposed.

Burning at the stake is too good for you.

Let me guess

Potemkine!

It was a sophisticated attack, wasn't it?

Reviewing our existing policies

Eclectic Man

"As part of our ongoing commitment to the privacy of personal information in our care, we are reviewing our existing policies and procedures, and are working to implement additional safeguards to further secure our information systems." =

"Oh Shit! we were supposed to keep this stuff secret and now someone has got hold of it, and this has been made public. Quick!, we need a press release to calm things down."

Maybe consider encrypted file store? Two-factor authentication? Firewalls?

I have no idea what their existing security policies are, but they certainly need reviewing by someone competent. My experience of 'high powered' types is that they are not that interested in IT security when it causes senior managers to have to do menial things like using a strong password to log on (which is not written down on a table attached to the computer), encrypting laptop hard drives, or even keeping said laptop out of public view when going for a drink or meal, or maybe not clicking on every link or attachment in every email they receive.

Or is 'reviewing our existing policies' actually a euphemism for 'looking for a scapegoat'*?

Not that I'm cynical or anything.

*Not one of the senior partners, probably an IT bod like 'head of IT security' or 'Chief Technical Officer' rather than the partner who didn't want to pay for IT security because (s)he got bored with the presentation.

Re: Reviewing our existing policies

nematoad

"The company has also offered those affected a 24-month subscription to credit monitoring, fraud consultation, and identity theft restoration services –"

Well that's very commendable but would it not have been cheaper to have actually thought about and implemented some sort of security on all your customers data?

As for keeping it quiet for five months surely some lawyer will see a pay day in that.

Re: Reviewing our existing policies

Eclectic Man

nematoad: "would it not have been cheaper to have actually thought about and implemented some sort of security on all your customers data?"

Depends, the company may well provide some those services (e.g. fraud consultation), and may be able to claim the costs back against their insurance policy or do some (perfectly legal) 'creative accountancy' to cover the costs.

The UK CIFAS (https://www.cifas.org.uk) seems quite cheap for an individual (about £25 for two years registration).

No tech here, we're lawyers

Anonymous Coward

The legal industry are dinosaurs when it comes to tech. Trade shows are big on photocopiers, and dicta-phones still used by some partners. I'll bet they still use faxes. One partner used her inbox as a filing system and had 16,000 emails there, which caused some problems on the back-end Exchange servers. Paralegals, unpaid interns, and young slaves are all much cheaper (and more tractable) than trying to automate what is essentially a boilerplate factory. Even first-movers such as Linklaters from the magic circle in the UK are still relatively tame when it comes to innovation. Frankly, Apple - and they all seem to love those devices - would seem to have the only chance of hauling them into the twentieth century, let alone the twenty-first.

Aladdin Sane

Building a guillotine costs around $1,200, lumber and hardware tools included. Draw your own conclusions.

Worst Month of 1981 for Downhill Skiing:
August. The lift lines are the shortest, though.
-- Steve Rubenstein