BlackCat claimed a breach of legal platform Casepoint used by US agencies
- Organization
- Casepoint
- Exploit
- Ransomware
- Industry
- Legal Technology
The ALPHV ransomware group, also known as BlackCat, listed the legal discovery platform Casepoint on its leak site at the end of May 2023 and claimed to have taken about two terabytes of data.
Casepoint's eDiscovery software is used by United States federal bodies including the Securities and Exchange Commission, the Department of Defense, the Department of Veterans Affairs, the Department of Agriculture and the federal courts, as well as corporate clients such as Marriott and the Mayo Clinic.
To support the claim, the group posted samples that reporters described as including a legal document, a government-issued identification card, health records from a Georgia hospital and an internal document attributed to the FBI. It also published what appeared to be credentials for Casepoint systems, and it pressed the company to begin negotiations.
Casepoint's first public response, from its vice president of marketing, said there was no validation that a breach had occurred and that no unusual data movement had been seen on its networks. The company then said it had activated its incident response protocols on May 30 and engaged an outside forensic firm. Co-founder and chief technology officer Vishal Rajpara said the platform remained fully operational with no service disruption, and the company said its government clients sat on a network separate from its commercial clients.
No ransom figure was disclosed and Casepoint did not confirm what, if anything, had been taken.
Sources
- TechCrunch, Legal tech firm Casepoint investigates breach after hackers claim theft of government data
- The Record, Legal services platform used by SEC, Pentagon investigating ransomware attack claims
- Security Affairs, BlackCat claims the hack of the Casepoint legal technology platform used by US agencies