Law firm battles ransomware and data exfiltration
After experiencing a ransomware attack, a law firm attempted to restore their systems from backups on their own. Working with a managed service provider (MSP), they felt like things were under control by the time they contacted Coalition¹ ² — until they learned the threat actor exfiltrated their data and threatened to leak it.
Initially, the law firm was hesitant to investigate the matter but suddenly felt an urgency to pay the ransom and protect their client data. Their Breach Response coverage kicked in, and they selected Coalition Incident Response (CIR)³ to begin the forensics investigation. The threat actor claimed to have stolen more than 100GB of data, but CIR suspected it could be much more.
To determine what data was exfiltrated and which clients would need to be notified, CIR engaged the threat actor and requested evidence of what data it had stolen. CIR ultimately received video confirmation of the threat actor deleting the files —and we determined no additional data beyond the amount they initially claimed was stolen.
Ultimately, CIR negotiated the ransom from six-figures to less than half of the demand, which was covered under the law firm’s policy. The law firm’s policy¹ is expected to cover CIR’s fees, notification costs, data mining, and legal fees.
Coalition¹ brings together active monitoring, incident response, and comprehensive insurance to solve cyber risk. To learn more, visit coalitioninc.com.
2. The claim scenarios described here are intended to show the types of situations that may result in claims. These scenarios should not be compared to any other claim. Whether or to what extent a particular loss is covered depends on the facts and circumstances of the loss, the terms and conditions of the policy as issued and applicable law. 3. Breach response included the engagement of an incident response firm; the insured selected Coalition Incident Response.
Ready to learn more?
Our brokers and policyholders get access to all of the intel we have on how to prevent, remedy, and recover from breaches of all kinds.
We’re bringing a new approach to managing digital risk, and the world has noticed. Here’s what people are saying about Coalition.
We’re a team of experts, backed by powerful partners, developing a safer world.
Coalition’s products are offered with the financial security of Allianz Group* (A.M. Best A+ rating), Arch Specialty Insurance Company (A.M. Best A+ rating), Ascot Group** (A.M Best A rating), Fortegra Group (A.M. Best A- rating), Lloyd’s of London (A.M. Best A rating), Swiss Re Corporate Solutions*** legal entities (A.M. Best A+ rating), Vantage Risk Specialty Insurance Company (A.M. Best A- rating), and Chaucer Insurance Company DAC (A.M. Best A rating).
© 2024 Coalition, Inc. | Licensed in all 50 states and D.C. | CA License # 0L76155
* Insurance products are offered in the U.S. by Coalition Insurance Solutions Inc., a licensed insurance producer and surplus lines broker. Insurance products may not be available in all states, For further details see here. ** Insurance products may be underwritten by Ascot Specialty Insurance Company, Ascot Insurance Company, or an affiliated company, which are members of Ascot Group. *** Insurance products may be underwritten by North American Capacity Insurance Company, Swiss Re Corporate Solutions America Insurance Corporation, or an affiliated company, which are members of Swiss Re Corporate Solutions. Fortegra® is the marketing name for the service contract and insurance operations of the subsidiaries of The Fortegra Group, Inc.