Menu
Browse

Cyber Incident Victim: Bricker & Eckler LLP

Date:

Jan 2021

Location:

United States of America

Summary

A ransomware attack compromised an Ohio law firm, Bricker & Eckler LLP, enabling unauthorized access to sensitive data including names, addresses, medical and educational records, driver’s licenses, and Social Security numbers. The breach impacted approximately 350 individuals associated with Michigan State University’s Title IX investigations through the firm’s contractor, INCompliance Consulting, exposing case files, reports, and emails, with six individuals experiencing personal data leaks. While the law firm recovered the accessed data, it acknowledged potential copying by attackers; MSU confirmed its internal systems remained secure and that ongoing cases were unaffected.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

The ransomware attack on Ohio-based law firm Bricker & Eckler LLP occurred between January 14 and January 31, 2021, when an unauthorized party gained access to the firm's systems. The attackers exfiltrated sensitive data including names, addresses, medical information, education records, driver's license numbers, and Social Security numbers. Bricker & Eckler served as legal counsel for INCompliance Consulting, a contractor managing Title IX investigations for Michigan State University (MSU). The compromised systems contained case files from INCompliance's work with MSU's Title IX program, exposing approximately 350 individuals involved in these investigations. Six specific individuals directly participating in Title IX cases had their personal information stolen. The law firm successfully recovered its data but acknowledged attackers might have copied the information during the breach period.

Cyber Incident Image

MSU confirmed its own systems remained secure and emphasized the breach originated entirely within Bricker & Eckler's infrastructure. The university stated the incident would not affect ongoing Title IX cases or investigations. Exposed documents included Title IX investigation reports, email communications, and case-related materials handled by INCompliance through its partnership with Bricker & Eckler. No evidence suggested broader dissemination of stolen data beyond the initial attackers at the time of disclosure. Bricker & Eckler implemented recovery procedures following the ransomware incident but did not specify whether a ransom was paid or detail technical containment measures. MSU coordinated notification efforts for affected individuals while maintaining operational continuity in its Title IX program.

Sources
Sources available to members
1 source