A creditor’s rights law firm based in Kansas has disclosed it was the victim of a ransomware attack, with the records of more than 150,000 individuals being involved, according to information that was posted to a website managed by the Maine Attorney General.
The big picture:
- The firm discovered suspicious activity on July 8, 2024, which included file encryption, a hallmark of ransomware attacks.
- An investigation determined that threat actors had access to the firm’s network from July 5 to July 8, exfiltrating data.
- By October 8, 2024, the firm confirmed that Social Security numbers, financial account details, and other personal identifiers were compromised.
What they’re saying:
“Although there is no evidence that any personal information has been misused, [the firm] is providing notice to potentially impacted individuals in an abundance of caution,” it stated in its filing with the Maine Attorney General’s Office.
- The firm began notifying affected individuals this week, offering them one year of free credit monitoring and identity restoration services.
- Impacted individuals were also given guidance on placing fraud alerts and security freezes on their credit files.
Between the lines:
- The firm has not disclosed which ransomware group was responsible or whether a ransom was paid. But given that nobody has claimed responsibility for the incident, that is sometimes an indication that the ransom was paid, according to a published report.
- The attack was reported to federal law enforcement, and additional security measures are being implemented.
- No reports suggest that compromised data has been misused, but financial institutions and collection agencies should monitor potential fraud trends tied to this breach.




