Law firm and cyber criminals clash over source of stolen data
Thursday, February 18, 2021
A dispute has broken out over the provenance of stolen data between US law firm Jones Day and the Cl0p ransomware gang after a number of the firm’s assets were leaked on the dark web.
Ilia Kolochenko, founder of Immuniweb, added: “It is highly likely that a third party or a vendor is the root cause of the alleged data breach. Cyber criminals usually start their 'shopping' by probing unprotected third parties that have access to valuable data of the victim. Currently disclosed details about the stolen data indicate that the incident has a narrow impact and only a limited number of customers and cases are affected by it. Also, even if some documents are marked as confidential or privileged, it does not necessarily mean that they still have, or ever had, this protectable status.
“This is, however, a good example where negotiations with the attackers could have minimised the damage, notably the reputational impact of the incident. Aggrieved clients and impacted third-parties may have a wide spectrum of legal claims against the law firm, spanning from violation of state privacy and data protection laws to legal malpractice. The incident deserves rapid investigation and transparent communications with the affected customers, if any.” Read Full Article
SiliconANGLE: Proofpoint sues Facebook over lookalike domain names used in security training
The Daily Swig: Software supply chain attacks – everything you need to know