CSIDB logo
Incident

Wilson Elser Moskowitz Edelman & Dicker

Incident posture

Attack window
Feb 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-01 00:00

Linked entities

Victim
Wilson Elser Moskowitz Edelman & Dicker
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A law firm experienced suspicious network activity, leading to the immediate shutdown of its systems as a precautionary measure. The firm enabled remote email access for attorneys while maintaining phone functionality and keeping offices operational, with no evidence of client data compromise identified during initial assessments. This incident occurred amid broader targeting of legal entities by cybercriminals using data exfiltration and extortion tactics, though the firm's specific intrusion vector and attacker affiliation remained unconfirmed in available reports.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On or around February 10, 2020, Wilson Elser Moskowitz Edelman & Dicker detected suspicious activity on its network, prompting an immediate response to contain the cybersecurity incident. The firm took its network offline as a containment measure while investigating the nature and scope of the intrusion. During this disruption, lawyers maintained email access through a remote system, ensuring some continuity in communications. The firm confirmed its phone systems remained operational and all physical offices stayed open despite the network outage. In a public statement issued on February 10, Wilson Elser stated there was no evidence suggesting client data had been compromised at that stage of the investigation. The firm did not disclose technical details regarding the attack vector, duration of network exposure, or specific systems affected beyond the general network shutdown. No ransomware demands or threat actor claims regarding Wilson Elser were referenced in available reports.

The incident occurred amid heightened law firm targeting by the Maze hacking group, which publicly claimed responsibility for breaching at least five other firms including Baker Wotring around the same timeframe. Maze employed a double-extortion model involving data exfiltration followed by ransom demands typically ranging from $1 million to $2 million, threatening to publish stolen materials like client fee agreements and case diaries if unpaid. While Baker Wotring suffered a confirmed "full dump" of its data by Maze, Wilson Elser's investigation outcomes regarding data exposure remained unspecified in initial disclosures. The firm's containment strategy prioritized operational continuity through alternative communication channels while forensic analysis continued. No subsequent updates regarding data compromise, ransom demands, or long-term operational impacts were documented in the immediate aftermath of the February 10 disclosure.

Sources

Sources available to members: 1 source.

CSIDB