Another US law firm reaches data breach settlement as cyber risks mount
Updated to include approval of Orrick settlement in paragraph 6.
By Sara Merken
Nov 8 (Reuters) -Florida business law firm Gunster has agreed to pay $8.5 million to resolve a proposed class action over a 2022 data breach that allegedly exposed the personal and health information of thousands of people.
Lawyers for the plaintiffs submitted the proposed settlement in Florida federal court on Thursday. It would resolve one of two cases filed this year against West Palm Beach-founded Gunster over a data security incident that allegedly compromised the personal data of nearly 10,000 people, including former and current clients and employees.
The agreement is subject to approval by U.S. District Judge Aileen Cannon. Gunster has denied the allegations and did not admit wrongdoing.
A Gunster representative on Friday said the firm will not comment on pending litigation. The firm's outside lawyers and a lawyer for the plaintiffs did not immediately respond to requests for comment.
The legal industry has been the target of growing cybersecurity attacks, including against law firms that often possess valuable confidential client information.
Orrick, Herrington & Sutcliffe in April reached an $8 million deal to settle a lawsuit over abreach that allegedly compromised personal data held by the firm on more than 600,000 people. A federal judge approved that settlement on Friday, according to an attorney for the plaintiffs.
Bryan Cave Leighton Paisner and snack food giant Mondelez reached a tentative $750,000 settlement in another data breach case last month.
The U.S. federal judiciary on Wednesday issued warnings about emails mimicking notifications of electronic court filings that seek to lure attorney recipients to a malicious website with computer viruses.
Plaintiff Mary Jane Whalen, a New York resident and former Gunster client, and plaintiff Christine Rona, a New York resident who was employed by Gunster to give healthcare services to the firm's high net worth clients, alleged in a complaint that Gunster failed to take adequate measures to protect personal information, among other claims.
Personal and sensitive information such as names, dates of birth, Social Security and banking information was "exfiltrated by cybercriminals" from the firm, the complaint said. Gunster in April issued data breach notifications that said there was unauthorized access to its document management file system.
The complaint alleged Gunster was likely a target because it is a large law firm that collects personal information and creates and maintains entities for wealthy clients.
Judge Cannon on Tuesday paused the other case against Gunster pending approval of the settlement.
The case is Whalen et al v. Gunster, Yoakley & Steward, U.S. District Court for the Southern District of Florida, No. 9:24-CV-80612.
For the plaintiffs: John Yanchunis of Morgan & Morgan and Brian Murray of Glancy Prongay & Murray
For Gunster: Kristine Brown of Alston & Bird and Jacqueline Arango of Akerman
Reporting by Sara Merken
면책조항: XM Group 회사는 체결 전용 서비스와 온라인 거래 플랫폼에 대한 접근을 제공하여, 개인이 웹사이트에서 또는 웹사이트를 통해 이용 가능한 콘텐츠를 보거나 사용할 수 있도록 허용합니다. 이에 대해 변경하거나 확장할 의도는 없습니다. 이러한 접근 및 사용에는 다음 사항이 항상 적용됩니다: (i) 이용 약관, (ii) 위험 경고, (iii) 완전 면책조항. 따라서, 이러한 콘텐츠는 일반적인 정보에 불과합니다. 특히, 온라인 거래 플랫폼의 콘텐츠는 금융 시장에서의 거래에 대한 권유나 제안이 아닙니다. 금융 시장에서의 거래는 자본에 상당한 위험을 수반합니다.
온라인 거래 플랫폼에 공개된 모든 자료는 교육/정보 목적으로만 제공되며, 금융, 투자세 또는 거래 조언 및 권고, 거래 가격 기록, 금융 상품 또는 원치 않는 금융 프로모션의 거래 제안 또는 권유를 포함하지 않으며, 포함해서도 안됩니다.
이 웹사이트에 포함된 모든 의견, 뉴스, 리서치, 분석, 가격, 기타 정보 또는 제3자 사이트에 대한 링크와 같이 XM이 준비하는 콘텐츠 뿐만 아니라, 제3자 콘텐츠는 일반 시장 논평으로서 "현재" 기준으로 제공되며, 투자 조언으로 여겨지지 않습니다. 모든 콘텐츠가 투자 리서치로 해석되는 경우, 투자 리서치의 독립성을 촉진하기 위해 고안된 법적 요건에 따라 콘텐츠가 의도되지 않았으며, 준비되지 않았다는 점을 인지하고 동의해야 합니다. 따라서, 관련 법률 및 규정에 따른 마케팅 커뮤니케이션이라고 간주됩니다. 여기에서 접근할 수 있는 앞서 언급한 정보에 대한 비독립 투자 리서치 및 위험 경고 알림을 읽고, 이해하시기 바랍니다.