/

Houser LLP Data Breach: What & How It Happened?

Houser LLP Data Breach: What & How It Happened?

Twingate Team

Jun 14, 2024

In May 2023, Houser LLP, a prominent law firm experienced a security incident resulting in unauthorized access to their network and the potential exposure of sensitive data. Although the firm took immediate steps to address the situation and engaged with the attackers, doubts remained about the complete resolution of the issue. This event has led to legal actions against the firm, with claims that insufficient security measures were in place to protect the data.

How many accounts were compromised?

The breach impacted data related to over 326,000 individuals.

What data was leaked?

The data exposed in the breach included names, Social Security numbers, driver's license numbers, individual tax identification numbers, financial account information, and medical information.

How was Houser LLP hacked?

The unauthorized third party gained access to Houser LLP's computer systems in early May 2023, encrypting certain files and exfiltrating sensitive data. The cybercriminals demanded a ransom in exchange for a decryption key, which Houser is reported to have paid. However, doubts remain about whether the stolen data was actually deleted as claimed by the attackers.

Houser LLP's solution

In response to the hacking incident, Houser LLP implemented several enhanced security measures to protect its systems and prevent future breaches. These steps included deploying RocketCyber, an endpoint detection and response tool, and implementing multi-factor authentication for Outlook 365, Net Extender VPN tunnel, and remote desktop connection. The firm also added ransomware detection software, utilized phishing simulation software, and conducted vulnerability assessment and penetration testing. While Houser LLP took these actions to strengthen its security, the effectiveness of these measures in preventing future incidents remains unclear.

How do I know if I was affected?

Houser LLP has not explicitly mentioned reaching out to affected users. If you believe you may have been affected by the breach, you can visit Have I Been Pwned to check your credentials.

What should affected users do?

In general, affected users should:

  • Change Your Passwords: Immediately update your passwords for any accounts that may have been compromised. Make sure the new passwords are strong and unique, not previously used on any other platform.

  • Reset Passwords for Other Accounts: If you've used the same or similar passwords for other online accounts, reset those as well. This is crucial as attackers often try using stolen passwords on multiple sites.

  • Enable Two-Factor Authentication (2FA): Activate 2FA on any affected accounts. Consider enabling this additional security feature on all other important online accounts to significantly reduce the risk of unauthorized access.

For more specific help and instructions related to Houser LLP's data breach, please contact Houser LLP's support directly.

Where can I go to learn more?

If you want to find more information on the Houser LLP data breach, check out the following news articles:

Rapidly implement a modern Zero Trust network that is more secure and maintainable than VPNs.

/

Houser LLP Data Breach: What & How It Happened?

Houser LLP Data Breach: What & How It Happened?

Twingate Team

Jun 14, 2024

In May 2023, Houser LLP, a prominent law firm experienced a security incident resulting in unauthorized access to their network and the potential exposure of sensitive data. Although the firm took immediate steps to address the situation and engaged with the attackers, doubts remained about the complete resolution of the issue. This event has led to legal actions against the firm, with claims that insufficient security measures were in place to protect the data.

How many accounts were compromised?

The breach impacted data related to over 326,000 individuals.

What data was leaked?

The data exposed in the breach included names, Social Security numbers, driver's license numbers, individual tax identification numbers, financial account information, and medical information.

How was Houser LLP hacked?

The unauthorized third party gained access to Houser LLP's computer systems in early May 2023, encrypting certain files and exfiltrating sensitive data. The cybercriminals demanded a ransom in exchange for a decryption key, which Houser is reported to have paid. However, doubts remain about whether the stolen data was actually deleted as claimed by the attackers.

Houser LLP's solution

In response to the hacking incident, Houser LLP implemented several enhanced security measures to protect its systems and prevent future breaches. These steps included deploying RocketCyber, an endpoint detection and response tool, and implementing multi-factor authentication for Outlook 365, Net Extender VPN tunnel, and remote desktop connection. The firm also added ransomware detection software, utilized phishing simulation software, and conducted vulnerability assessment and penetration testing. While Houser LLP took these actions to strengthen its security, the effectiveness of these measures in preventing future incidents remains unclear.

How do I know if I was affected?

Houser LLP has not explicitly mentioned reaching out to affected users. If you believe you may have been affected by the breach, you can visit Have I Been Pwned to check your credentials.

What should affected users do?

In general, affected users should:

  • Change Your Passwords: Immediately update your passwords for any accounts that may have been compromised. Make sure the new passwords are strong and unique, not previously used on any other platform.

  • Reset Passwords for Other Accounts: If you've used the same or similar passwords for other online accounts, reset those as well. This is crucial as attackers often try using stolen passwords on multiple sites.

  • Enable Two-Factor Authentication (2FA): Activate 2FA on any affected accounts. Consider enabling this additional security feature on all other important online accounts to significantly reduce the risk of unauthorized access.

For more specific help and instructions related to Houser LLP's data breach, please contact Houser LLP's support directly.

Where can I go to learn more?

If you want to find more information on the Houser LLP data breach, check out the following news articles:

Rapidly implement a modern Zero Trust network that is more secure and maintainable than VPNs.

Houser LLP Data Breach: What & How It Happened?

Twingate Team

Jun 14, 2024

In May 2023, Houser LLP, a prominent law firm experienced a security incident resulting in unauthorized access to their network and the potential exposure of sensitive data. Although the firm took immediate steps to address the situation and engaged with the attackers, doubts remained about the complete resolution of the issue. This event has led to legal actions against the firm, with claims that insufficient security measures were in place to protect the data.

How many accounts were compromised?

The breach impacted data related to over 326,000 individuals.

What data was leaked?

The data exposed in the breach included names, Social Security numbers, driver's license numbers, individual tax identification numbers, financial account information, and medical information.

How was Houser LLP hacked?

The unauthorized third party gained access to Houser LLP's computer systems in early May 2023, encrypting certain files and exfiltrating sensitive data. The cybercriminals demanded a ransom in exchange for a decryption key, which Houser is reported to have paid. However, doubts remain about whether the stolen data was actually deleted as claimed by the attackers.

Houser LLP's solution

In response to the hacking incident, Houser LLP implemented several enhanced security measures to protect its systems and prevent future breaches. These steps included deploying RocketCyber, an endpoint detection and response tool, and implementing multi-factor authentication for Outlook 365, Net Extender VPN tunnel, and remote desktop connection. The firm also added ransomware detection software, utilized phishing simulation software, and conducted vulnerability assessment and penetration testing. While Houser LLP took these actions to strengthen its security, the effectiveness of these measures in preventing future incidents remains unclear.

How do I know if I was affected?

Houser LLP has not explicitly mentioned reaching out to affected users. If you believe you may have been affected by the breach, you can visit Have I Been Pwned to check your credentials.

What should affected users do?

In general, affected users should:

  • Change Your Passwords: Immediately update your passwords for any accounts that may have been compromised. Make sure the new passwords are strong and unique, not previously used on any other platform.

  • Reset Passwords for Other Accounts: If you've used the same or similar passwords for other online accounts, reset those as well. This is crucial as attackers often try using stolen passwords on multiple sites.

  • Enable Two-Factor Authentication (2FA): Activate 2FA on any affected accounts. Consider enabling this additional security feature on all other important online accounts to significantly reduce the risk of unauthorized access.

For more specific help and instructions related to Houser LLP's data breach, please contact Houser LLP's support directly.

Where can I go to learn more?

If you want to find more information on the Houser LLP data breach, check out the following news articles: