
California-based law firm Houser LLP said that the ransomware attack it suffered last year compromised the sensitive personal information of more than 690,000 individuals.
Based in Irvine, California, Houser LLP is an American commercial and business litigation law firm that mainly caters to Fortune 500 companies. The firm has more than 10 offices across the U.S. and provides legal services to commercial businesses and financial institutions.
In a notice of data breach filed with the Office of the Maine Attorney General on February 28, Houser said that in May last year, it discovered that malicious actors had encrypted certain files in its computer systems.
The firm said that after it discovered the breach, it launched an investigation, with the assistance of third-party forensic specialists, to understand the nature and scope of the incident.
“The investigation determined that there was unauthorised access to the Houser network between May 7, 2023, and May 9, 2023, during which time certain files were copied and taken from the network. However, in June 2023, the unauthorised actor informed Houser that they deleted copies of any stolen data and would not distribute any stolen files,” the firm said.
The law firm worked with cyber security experts to understand whether the files accessed by the threat actors contained any sensitive personal information of individuals associated with the firm.
The investigation, concluded on January 18, revealed that the malicious actors were able to access personal information such as names and other personal identifiers, financial account numbers, credit and debit card numbers along with security codes, access codes, passwords and PINs.
The initial filing with the state regulator also revealed that the data security incident compromised the personal information of at least 326,386 individuals. On March 26, the firm revealed in a fresh filing that the data security incident impacted another 364,312 individuals.
The company has urged all affected individuals to remain vigilant, review their credit reports and financial statements on a regular basis, and report suspicious transactions to relevant law enforcement authorities.
It is also offering one year of complimentary credit monitoring and identity theft restoration through IDX to all the individuals affected by the data breach. Also, it has set up a dedicated helpline where affected individuals can call and get their queries answered.
On May 10, the notorious ALPHV/BlackCat ransomware group claimed responsibility for the cyber attack on Houser LLP and listed the company as a victim on its data leak site.
The group claimed to be in possession of 1.5TB of company data including internal company data, employees personal data, CVs, DLs, IDs, SSNs, financial reports, agreements, insurance, client documentation including DLs, IDs, SSNs, financial data, credit card information, loan data, agreements, complete network map including credentials for local and remote services, and more.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543