Menu
Browse

Cyber Incident Victim: Seyfarth Shaw LLP

Date:

Oct 2020

Location:

United States of America

Summary

Seyfarth Shaw LLP experienced a sophisticated ransomware attack that encrypted numerous systems and disrupted email services, though phone systems remained operational. The firm detected unauthorized activity promptly, contained the malware's spread, and initiated precautionary shutdowns of affected infrastructure. While no evidence indicated client or internal data was accessed or exfiltrated, the incident required extensive recovery efforts coordinated with the FBI. The attack mirrored simultaneous targeting of other entities, underscoring its aggressive nature. The organization prioritized restoring services and safeguarding confidential information while maintaining client communication through alternative channels during system restoration.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On October 10, 2020, Seyfarth Shaw LLP experienced a ransomware attack described as sophisticated and aggressive. The firm’s monitoring systems detected unauthorized activity consistent with ransomware, prompting immediate action by its IT team to contain the attack and prevent further spread across its network. The attackers encrypted numerous firm systems, leading Seyfarth to proactively shut down affected infrastructure as a precautionary measure. While the attack disrupted operations, the firm’s initial investigation found no evidence that client or internal data had been accessed or exfiltrated. Seyfarth engaged the FBI to assist in the response and initiated recovery efforts to restore encrypted systems. The incident coincided with attacks on other unspecified entities, suggesting a broader campaign targeting multiple organizations simultaneously.

Cyber Incident Image

The ransomware attack significantly impacted Seyfarth’s email systems, which remained offline following the incident, though phone systems continued functioning. To maintain client communication, the firm established an alternative contact form on its website and committed to providing regular updates. Operational disruptions included encrypted systems requiring shutdowns, but the firm prioritized restoring services while safeguarding client confidentiality. Seyfarth publicly disclosed the attack on the same day it occurred, a move that preempted potential reputational damage from threat actors leaking news of the compromise. The notification emphasized ongoing coordination with law enforcement and round-the-clock efforts to recover systems, though it did not specify whether ransomware payments were considered or made. No subsequent data leaks or auctions tied to Seyfarth appeared on ransomware group Dedicated Leak Sites (DLS), consistent with other law firms that refused ransom demands in prior incidents.

Sources
Sources available to members
1 source