Berkeley Research Group discloses ransomware attack during LBO debt sale
- Organization
- Berkeley Research Group
- Exploit
- Ransomware
- Industry
- Business Services
Berkeley Research Group, a United States consulting and expert services firm, said it identified suspicious network activity on 2 March 2025 with indicators of compromise consistent with a ransomware attack. In a public notice, the firm said the unauthorised activity took place between 28 February and 2 March.
BRG took systems offline to contain the intrusion, engaged outside cybersecurity professionals and began a forensic investigation. Consulting.us, citing Bloomberg's reporting, said the firm retained the data security practice Octillo Law and Booz Allen Hamilton's cyber team, and that the attacker claimed to have stolen data and encrypted files before issuing multiple ransom demands.
The firm's notice said the categories of information potentially involved included names, addresses, dates of birth, Social Security numbers, government identification numbers, financial account and payment card details, login credentials, medical records and health insurance information. BRG said it was reporting the incident to relevant government agencies.
The attack landed while BRG was in the middle of a roughly $700 million leveraged loan sale financing TowerBrook Capital Partners' majority equity investment in the firm, a transaction that had been expected to close in April 2025. BRG said it reset credentials across its user base, expanded endpoint detection monitoring and tightened access controls, and it set up a toll-free assistance line along with credit monitoring guidance for affected individuals. BRG, TowerBrook, Octillo and Booz Allen declined to comment to Bloomberg.