Cyber Incident Victim: Wiggin and Dana LLP
Date:
Jul 2021
Location:
United States of America
Summary
A Connecticut law firm experienced a ransomware attack involving unauthorized access to its systems, with confirmation that certain files may have been compromised. The investigation determined that sensitive information potentially exposed included names, dates of birth, Social Security numbers, financial account details, medical records, and government-issued identification numbers. While the full scope of accessed or acquired data could not be definitively established, the firm initiated precautionary notifications due to the presence of these data types in affected systems. Forensic specialists assisted in the ongoing review of impacted systems to identify compromised information.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Wiggin and Dana LLP, a Connecticut-based law firm, experienced a cybersecurity incident involving unauthorized access to its systems. The firm first received confirmation on July 20, 2021, that certain files within their environment may have been accessed by an unauthorized actor. While the exact timeline remains unclear—with no public disclosure of when the initial intrusion occurred or when detection first took place—the July confirmation date marked the pivotal point in their response. The firm engaged forensic specialists to conduct a thorough review of the incident, though this process proved time-consuming due to the complexity of determining the full scope of compromised data. Despite investigative efforts, Wiggin and Dana could not conclusively identify all specific information accessed or exfiltrated by the threat actor during the breach.

In response to these uncertainties, the firm adopted a cautious approach by issuing breach notifications while their forensic review remained ongoing. The investigation revealed that affected systems contained multiple categories of sensitive information at the time of the incident, including names, dates of birth, Social Security numbers, financial account details, medical treatment information, and government-issued identification numbers. Although the firm had not finalized determining precisely which individuals' data was compromised, they proceeded with notifications due to the confirmed presence of these high-risk data types in the accessed systems. The incident disclosure, made public in October 2021, characterized the event as a ransomware attack according to third-party reporting, though the firm's official communications emphasized data access rather than encryption demands. No further details regarding containment measures, threat actor attribution, or data restoration processes were disclosed in the available public statements.
