Proskauer Rose left confidential client M&A files exposed on an unsecured cloud server

Organization
Proskauer Rose
Exploit
Misconfiguration
Industry
Legal Services

Proskauer Rose, the New York headquartered law firm, confirmed in April 2023 that confidential client material from its mergers and acquisitions practice had been left on an unsecured cloud server. The data was held on a Microsoft Azure server left readable to anyone who knew the address, with no password required.

TechCrunch, which first reported the exposure on 6 April 2023, put the volume at roughly 184,000 files. They included private and privileged financial and legal documents, contracts, non-disclosure agreements and material tied to high profile acquisitions. The files were surfaced through GrayHatWarfare, a searchable index of publicly visible cloud storage. TechCrunch reported the data was understood to have been public for at least six months.

Proskauer said an outside vendor it had retained to build an information portal on a third party cloud storage platform had not properly secured it. The firm declined to name the vendor. It said its IT security team took immediate steps to reconfigure the site and secure the data. TechCrunch reported in early April 2023 that Proskauer had resolved the exposure about two weeks earlier. Internal and external cybersecurity experts were engaged to investigate.

As of early April the firm had not yet notified affected clients, saying it would communicate with all affected parties once it had enough information to do so responsibly. Proskauer's client roster includes Major League Baseball and Morgan Stanley.

Sources