CSIDB logo
Incident

Allen & Overy

Incident posture

Attack window
Nov 2023
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2026-01-05 21:38

Linked entities

Victim
Allen & Overy
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Allen & Overy experienced a cyberattack compromising a limited number of servers, though core systems such as email and document management remained unaffected. The firm maintained normal operations with minor disruptions from containment measures while assessing potential data exposure and notifying impacted clients. Its technical team, supported by an independent cybersecurity adviser, implemented immediate containment actions, with the investigation ongoing. The incident occurred amid a planned merger with Shearman & Sterling, which confirmed no system impact due to separate infrastructures.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Allen & Overy experienced a cyberattack targeting a limited number of its servers, as confirmed by the firm in a November 2023 statement characterizing the event as a “data incident.” The breach did not compromise core systems critical to daily operations, including email and document management platforms. Immediate containment measures were implemented by the firm’s technical response team in collaboration with an independent cybersecurity adviser, though these steps caused some operational disruptions. The law firm emphasized business continuity despite these challenges, stating it continued to operate normally overall. An investigation remained ongoing to determine the scope of compromised data, with affected clients being notified as a priority. The firm reiterated that safeguarding client data confidentiality was an “absolute priority” in its public communications.

This incident occurred during a pivotal period for Allen & Overy, following partner approval in October 2023 of its planned merger with Shearman & Sterling to form a combined entity with approximately 3,900 lawyers. The firm explicitly confirmed the cyberattack would not affect Shearman & Sterling’s systems, citing their operational separation ahead of the merger’s expected May 2024 completion. The breach aligns with a broader trend of cyberattacks targeting major law firms, including Bryan Cave Leighton Paisner, Proskauer Rose, Kirkland & Ellis, DLA Piper, K&L Gates, and Orrick Herrington & Sutcliffe in recent months. No specifics regarding attack vectors, threat actors, or data exfiltration were disclosed publicly. The investigation focused on identifying impacted data while maintaining containment protocols established during the initial response phase.

Sources

Sources available to members: 1 source.

CSIDB