Thompson Hine has a broad range of experience in helping organizations respond to cyberattacks, including ransomware attacks and data breaches. The following are representative examples.
- Served as breach coach for construction consultant with respect to Play ransomware attack; retained digital forensic expert and threat actor negotiators and advised on data breach notification obligations with respect to potential compromise of current and former employees' sensitive HR data.
- Assisted business associate technology company with responding to Play ransomware attack, including with respect to threat actor negotiations and HIPAA security incident and breach reporting obligations.
- Assisted school district in responding to RansomHub cybersecurity incident, including with respect to threat actor communications, sanctions checks, digital forensics, and drafting and disseminating data subject notices pursuant to FERPA and U.S. state law.
- Advised a global manufacturer on responding to ransomware attack by Black Basta that encrypted its VMware ESXi; representation included retaining an IT consultant to restore data from backups and analyze logs derived from third-party security tool to identify compromised data sets, and rendering legal counsel on complying with data breach notification obligations.
- Assisted a global manufacturing client in responding to use of compromised credentials to access third-party HR data platform, including retaining third-party IT consultant to undertake log analysis, engaging platform host to assess liability and responsibility, advising on data breach notification obligations and helping client raise Computer Fraud and Abuse Act (CFAA) and Stored Communications Act (SCA) claims against former employee responsible for the attack.
- Advised a global power management corporation (covered entity) on responding to notification that its business associate was subject to a cybersecurity event initiated by the Karakurt Data Extortion Group; representation included reviewing IT consultant reports, counseling client on legal remedies, and advising on data incident notification obligations under federal and state law, including state-specific reporting requirements applicable to certain insurance licensees.
- Assisted a large U.S.-based aviation services and ground handling company in responding to business email compromise that resulted in fraudulent invoices and misdirected payments, and unauthorized access to sensitive personal data; representation included advising on complying with data breach notification rules and drafting breach letters to impacted data subjects, engaging the client’s cyber insurance carrier, retaining an IT consultant to undertake an independent review of client’s email infrastructure and rules and to facilitate data mining, and performing internal review of compromised documents.
- Counseled a telecom industry client on responding to fraudulent invoicing by leading an investigation into a potential email system compromise, including retaining an IT consultant, reviewing and amending terms of service with applicable parties, engaging client’s cyber insurance carrier and seeking approvals in accordance with cyber policy, and providing legal counsel with respect to investigatory findings.
- Assisted a managed service provider in responding to Makop ransomware brute force attack impacting client’s customers’ servers and other devices, including by retaining independent digital forensic investigators and providing advice and counsel related to potential litigation arising from the same.
- Helped a global manufacturer respond to a Royal ransomware and extortion attack, including retaining an independent incident response and digital forensic consultant; retaining a separate ransomware negotiator; leading data mining efforts; issuing litigation holds; and coordinating with foreign counsel on the proper data incident notifications to data subjects and regulatory officials in the United States, European Economic Area, United Kingdom and Australia.
- Assisted nationally recognized business associate in responding to business email compromise, including retaining third-party digital forensic and incident response consultant, assessing breadth of compromise including to personal data, and counseling on data breach notification process under federal and state law.
- Advised national restaurant chain client on responding to security compromise wherein threat actor gained unauthorized access to loyalty program and made unauthorized purchases from consumer accounts, including providing legal analysis of data breach notification obligations and advising on third-party digital forensic consultant to undertake independent investigation.
- Advised U.S.-based publicly traded multinational corporation on whether inclusion of social security numbers on health plan communications transmitted via mail from business associate would be considered a data breach for purposes of federal and state data breach notification laws.
- Assisted a client in responding to a data security incident impacting sensitive, business confidential records about its security controls that were in the custody and control of a third-party consultant, including retention of an independent third-party digital forensic and incident response organization.
- Assisted a consumer app provider in investigating security vulnerabilities and anomalies and potential unauthorized access and misuse of consumer data stored therein. Provided legal advice and guidance on whether the client’s obligations with respect to U.S. state data breach notification laws were implicated.
- Assisted a global manufacturing company in responding to a Lockbit 3.0 ransomware and extortion attack, including by retaining a third-party incident response team and ransomware negotiator, conducting OFAC checks, issuing litigation holds, and providing formal notification to data subjects, regulators and credit monitoring agencies.
- Assisted a client in analyzing and addressing a security incident involving potential exposure of employees' PHI resulting from a malware attack on the servers of a vendor providing printing and mailing services to the client's group health insurance provider, including by providing counsel on the applicability of federal (HIPAA) breach notifications laws.
- Helped a client respond to a data breach involving potential exposure of employees' PHI resulting from a credential stuffing attack on its pharmacy benefit manager's mobile app. In this type of attack, bad actors collect user IDs and passwords exposed in data breaches and use them to attempt to access unrelated online accounts and portals.
- Assisted a client by providing legal analysis on its data breach reporting obligations arising from the unauthorized disclosure of internal records containing account usernames and passwords belonging to third-party clients and vendors.
- Advised a client on responding to and remediating a data breach resulting from a credential stuffing attack on its pharmacy benefit manager, including providing analysis and advice regarding government agency reporting and consumer notification and advice on contractual rights and remedies.
If your organization has suffered a data breach or incident, please contact us at any time (24/7) at DataBreachResponse@ThompsonHine.com or fill out our online form below.



