AmLaw 100 firm Bryan Cave Leighton Paisner — with significant Texas operations — suffered a data breach affecting 585,000 individuals whose data was held on behalf of client organizations. Sensitive PII including Social Security numbers was exfiltrated.
Exfiltration via compromised file-sharing and collaboration platform credentials. Threat actor moved quietly through document management systems over weeks before detection. Extensive client PII was accessible without data-at-rest encryption on sensitive file stores.
Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →
| Regime | Standard / Citation | Gap Identified |
|---|---|---|
| ABA | ABA Rule 1.6(c) | Reasonable measures to prevent unauthorized disclosure of client information |
| ABA | ABA Formal Opinion 477R | Security for communication and storage of client confidential information |
| TDPA | Tex. B&C Code §521.053 | Texas resident PII breach notification obligations triggered |
CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.
Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.