Skip to main content
Cyberatttack & Data Breach Response

Practices

Cyberattack Response Experience

Thompson Hine has a broad range of experience in helping organizations respond to cyberattacks, including ransomware attacks and data breaches. The following are representative examples.

  • Served as breach coach for multinational, publicly traded company in the food and beverage industry in its response to a Redact (or RedAct) exfiltration and extortion attack, including providing guidance on compliance with the SEC’s cybersecurity incident disclosure materiality rule, engaging in threat actor negotiations, coordinating with counsel in the European Union on GDPR notification obligations, and advising on compliance with U.S. data breach notification laws.
  • Assisted a global provider of data, analytics, and workflow solutions with responding to Jasper Sleet incident involving fraudulent remote IT worker operations associated with North Korean threat operations; representation included retaining IT security consultant to assess malicious activity, leading internal investigation into insider threat activity, engaging with federal, state and local law enforcement agencies, and advising on compliance with regulatory notification process.
  • Provided incident response counsel to a dealer management software provider with respect to a pure extraction and ransom (PEAR)-based ransomware incident, including negotiating with threat actor and drafting and furnishing formal notice of the incident to business customers, individuals, and regulators.
  • Provided incident response counsel to regional commercial glass contractor with respect to Qilin-based ransomware incident, including negotiating with threat actor, drafting and furnishing formal notice of the incident to current and former employees, and engaging with law enforcement.
  • Assisted national manufacturer of telecommunications devices with responding to Akira-based ransomware event, including with respect to filing 8-K reports in order to comply with SEC rules and regulations governing cybersecurity incident disclosures for publicly traded companies.
  • Advised county school district with respect to INTERLOCK ransomware incident affecting on-premises and backup systems, including working with the state’s rapid response incident response team, participating in threat actor negotiations, and advising on federal (FERPA) and state data breach response laws.
  • Provided counsel on global manufacturer's response to Cl0p exploitation of a zero-day vulnerability in Cleo managed file transfer software that resulted in exfiltration of confidential information and personal data pertaining to client; representation included advising on data breach notification obligations and third-party recovery options.
  • Assisted county school district with its response to the unauthorized exfiltration of students' and educators' personal information from the PowerSchool data platform; drafted notification to students, parents and administration, undertook data mining, advised on compliance with federal education privacy law (FERPA) recordkeeping obligations, and advised on federal and state data breach notification obligations.
  • Represented energy industry client in its response to Eldorado ransomware incident impacting its third-party payroll service provider. Engagement included working with local counsel in the Middle East to facilitate data subject and regulatory notifications and providing guidance on indemnification and breach of contract remedies.
  • Assisted manufacturer of high-quality retail and foodservice desserts in responding to Akira ransomware attack. Retained digital forensic and security consultant to lead remediation and restoration, engaged in threat actor negotiations, drafted data breach incident notifications in multiple languages, procured credit monitoring services for affected data subjects, and furnished formal notification of incident to regulatory authorities.
  • Assisted third-party healthcare benefits administrator with responding to theft at corporate offices which compromised hard copies of records containing protected health information. Representation included engaging with client's customers (employers) about the incident, drafting notice of the incident to impacted employees, retaining credit monitoring services for affected data subjects, and submitting formal notice of the incident to law enforcement and federal regulatory authorities.
  • Served as breach coach for construction consultant with respect to Play ransomware attack; retained digital forensic expert and threat actor negotiators and advised on data breach notification obligations with respect to potential compromise of current and former employees' sensitive HR data.
  • Assisted business associate technology company with responding to Play ransomware attack, including with respect to threat actor negotiations and HIPAA security incident and breach reporting obligations.
  • Assisted school district in responding to RansomHub cybersecurity incident, including with respect to threat actor communications, sanctions checks, digital forensics, and drafting and disseminating data subject notices pursuant to FERPA and U.S. state law.
  • Assisted client in responding to data incident involving potential exposure of customers' personally identifiable information as a result of improper publication by client's mobile services provider; representation included providing counsel on the applicability of international and state data breach notifications laws, advising on notifications to client’s business customers, and responding to additional inquiries.
  • Assisted client in responding to intrusion into a remote employee’s personal and professional devices, including leading forensic investigation and advising on federal and state data breach notification laws.
  • Assisted textile manufacturer with response to business email compromise that resulted in unauthorized access to unencrypted payment card information; advised on data mining process and complying with U.S. state data breach notification laws with respect to informing impacted customers and regulatory agencies.
  • Assisted global manufacturing company in responding to BlackSuit double extortion ransomware attack that impacted client's operations in dozens of countries. Representation included retaining digital forensic consultant, negotiating $25 million ransom demand, engaging with law enforcement and regulatory authorities, and drafting and processing formal data incident notification communications to impacted employees, customers, and other third parties in accordance with the client’s data breach notification obligations.
  • Advised public school district on its response to unauthorized intrusion into its information networks; retained digital forensic investigator and advised on data breach reporting obligations to impacted students, administrators and other third parties, and with respect to state comptroller.
  • Assisted futures broker in responding to business email compromise that resulted in fraudulent wire transfer, including with respect to digital forensic investigation, data mining, Suspicious Activity Reporting (SAR) to the Treasury Department and data breach notification laws and regulations.
  • Assisted multiple clients whose employee health care plans were indirectly affected by the Change Healthcare ransomware attack, including by providing legal and policy advice regarding informal and formal notifications to impacted employees and regulatory authorities.
  • Assisted manufacturer with its response to and remediation of data incident resulting from BlackSuit ransomware attack which disrupted client’s global business operations, including by engaging law enforcement to address unique data retrieval capabilities, negotiating $20 million ransom demand, undertaking data mining, and furnishing data incident notification to affected parties and regulatory officials.
  • Assisted client in responding to potential exposure of PII resulting from a business email compromise, including by providing counsel on risk exposure due to insufficient forensic evidence of PII accessed and customer proprietary network information (CPNI) law enforcement reporting requirements.
  • Advised pharmaceutical company on responding to potential exposure of personally identifiable information (PII) and protected health information (PHI) resulting from ransomware attack on a clinical trial partner, including by providing counsel on the applicability of federal (HIPAA) and state data breach notifications laws.
  • Assisted technology services provider in responding to intrusion into its customer-facing platform. Provided guidance on contractual and legal notification obligations with respect to its customers (i.e., educational institutions) regarding unauthorized access to their data, including personal data related to students, teachers and school administrators, advised on data mining processes, retained credit monitoring services and drafted notices to customers and affected parties.
  • Advised a global manufacturer on responding to ransomware attack by Black Basta that encrypted its VMware ESXi; representation included retaining an IT consultant to restore data from backups and analyze logs derived from third-party security tool to identify compromised data sets, and rendering legal counsel on complying with data breach notification obligations.
  • Assisted a global manufacturing client in responding to use of compromised credentials to access third-party HR data platform, including retaining third-party IT consultant to undertake log analysis, engaging platform host to assess liability and responsibility, advising on data breach notification obligations and helping client raise Computer Fraud and Abuse Act (CFAA) and Stored Communications Act (SCA) claims against former employee responsible for the attack.
  • Advised a global power management corporation (covered entity) on responding to notification that its business associate was subject to a cybersecurity event initiated by the Karakurt Data Extortion Group; representation included reviewing IT consultant reports, counseling client on legal remedies, and advising on data incident notification obligations under federal and state law, including state-specific reporting requirements applicable to certain insurance licensees.
  • Assisted a large U.S.-based aviation services and ground handling company in responding to business email compromise that resulted in fraudulent invoices and misdirected payments, and unauthorized access to sensitive personal data; representation included advising on complying with data breach notification rules and drafting breach letters to impacted data subjects, engaging the client’s cyber insurance carrier, retaining an IT consultant to undertake an independent review of client’s email infrastructure and rules and to facilitate data mining, and performing internal review of compromised documents.
  • Counseled a telecom industry client on responding to fraudulent invoicing by leading an investigation into a potential email system compromise, including retaining an IT consultant, reviewing and amending terms of service with applicable parties, engaging client’s cyber insurance carrier and seeking approvals in accordance with cyber policy, and providing legal counsel with respect to investigatory findings.
  • Assisted a managed service provider in responding to Makop ransomware brute force attack impacting client’s customers’ servers and other devices, including by retaining independent digital forensic investigators and providing advice and counsel related to potential litigation arising from the same.
  • Helped a global manufacturer respond to a Royal ransomware and extortion attack, including retaining an independent incident response and digital forensic consultant; retaining a separate ransomware negotiator; leading data mining efforts; issuing litigation holds; and coordinating with foreign counsel on the proper data incident notifications to data subjects and regulatory officials in the United States, European Economic Area, United Kingdom and Australia.
  • Assisted nationally recognized business associate in responding to business email compromise, including retaining third-party digital forensic and incident response consultant, assessing breadth of compromise including to personal data, and counseling on data breach notification process under federal and state law.
  • Advised national restaurant chain client on responding to security compromise wherein threat actor gained unauthorized access to loyalty program and made unauthorized purchases from consumer accounts, including providing legal analysis of data breach notification obligations and advising on third-party digital forensic consultant to undertake independent investigation.
  • Advised U.S.-based publicly traded multinational corporation on whether inclusion of social security numbers on health plan communications transmitted via mail from business associate would be considered a data breach for purposes of federal and state data breach notification laws.
  • Assisted a client in responding to a data security incident impacting sensitive, business confidential records about its security controls that were in the custody and control of a third-party consultant, including retention of an independent third-party digital forensic and incident response organization.
  • Assisted a consumer app provider in investigating security vulnerabilities and anomalies and potential unauthorized access and misuse of consumer data stored therein. Provided legal advice and guidance on whether the client’s obligations with respect to U.S. state data breach notification laws were implicated.
  • Assisted a global manufacturing company in responding to a Lockbit 3.0 ransomware and extortion attack, including by retaining a third-party incident response team and ransomware negotiator, conducting OFAC checks, issuing litigation holds, and providing formal notification to data subjects, regulators and credit monitoring agencies.
  • Assisted a client in analyzing and addressing a security incident involving potential exposure of employees' PHI resulting from a malware attack on the servers of a vendor providing printing and mailing services to the client's group health insurance provider, including by providing counsel on the applicability of federal (HIPAA) breach notifications laws.
  • Helped a client respond to a data breach involving potential exposure of employees' PHI resulting from a credential stuffing attack on its pharmacy benefit manager's mobile app. In this type of attack, bad actors collect user IDs and passwords exposed in data breaches and use them to attempt to access unrelated online accounts and portals.
  • Assisted a client by providing legal analysis on its data breach reporting obligations arising from the unauthorized disclosure of internal records containing account usernames and passwords belonging to third-party clients and vendors.
  • Advised a client on responding to and remediating a data breach resulting from a credential stuffing attack on its pharmacy benefit manager, including providing analysis and advice regarding government agency reporting and consumer notification and advice on contractual rights and remedies.
Net Diligence Breach Coach Silver
The Data Protection Guidebook 2026
Data Protection Map

If your organization has suffered a data breach or incident, please contact us any time (24/7) at DataBreachResponse@ThompsonHine.com.

A survey of U.S. Federal and State Laws, Statutes, and Regulations Governing Data Breach Notification, Biometric Information, Cybersecurity, and Data Privacy*

*The content is for general information purposes only and does not constitute legal or professional advice.

Businesses must protect the privacy and security of the personal data and confidential information in their custody and control. However, in today’s dynamic threat environment, businesses are facing evolving risks to their information technology (IT) systems and networks. To mitigate these risks, a business should build a data protection program tailored to its unique concerns and threats. Central to developing a data protection program is creating, implementing, and maintaining a clear and concise data incident response plan (IRP) that outlines the measures and tools needed to prepare for and respond to an actual or reasonably suspected data breach.

This checklist provides an outline of the critical elements a business should address or consider when creating an IRP. Full access to the checklist is available here (pdf).


  1. Governance and responsibilities. The IRP must identify the key individuals who have roles in the security incident response process.
  2. Incident Response Coordinator. The business should delegate authority to one person, an Incident Response Coordinator, to oversee data breach response efforts.
  3. Incident Response Team (IRT). An IRT is a predetermined group of employees, contractors, and other resources responsible for responding to data security incidents.
  4. Incident response procedures. The IRP should include procedures and protocols that address detection and discovery; assessment and escalation; IRT investigation and analysis; and containment, remediation, and recovery.
  5. Evidence preservation. The IRT should direct appropriate internal or external resources to capture and preserve evidence during the investigation, analysis, and response activities.
  6. Communications and notifications. The IRT, in coordination and consultation with legal counsel, should consider developing a communication plan for both internal and external stakeholders.
  7. Post-incident response. Following a security incident or data breach, a business should, at least periodically, reconvene the IRT to assess the incident, the effectiveness of the response, and any remedial measures needed to mitigate risk.

Full access to the checklist is available here (pdf).

The First 72 Hours:

Critical Steps Following a Data Breach

When it comes to a data breach, what you do in the first few hours and days can mean the difference between containing the risks and losses and losing control of events. As the minutes and hours tick by, the financial and reputational consequences you face may be quickly multiplying. According to the 2019 Cost of a Data Breach Report (Ponemon Institute/IBM Security), the average total cost of a data breach globally is $3.92 million (USD), and in the United States that number more than doubles to $8.19 million. And that doesn’t even begin to account for the potential harm to your public image. It is in the best interests of your company and its employees and customers that you quickly assess the situation, notify the proper parties, and begin the investigation and remediation process. In fact, if you conduct business in the European Union, its General Data Protection Regulation in most cases requires you to report a breach to the supervisory authority within 72 hours of its discovery.

Would you know where to begin? The good news is that you don’t have to. Our Privacy & Cybersecurity team has the experience and resources to help you quickly and effectively respond to a data breach. Our professionals have substantial experience in managing data incident response scenarios, and we can deliver an efficient, disciplined and effective response plan. And we provide our services for a fixed fee, so you know the cost up front.

Here’s how we can help:

Initial Assessment

  • Create and convene (with general counsel/CISO) the incident response team
  • Identify and interview knowledgeable personnel
  • Investigate source, scope and nature of incident, including what was lost (physical or data) and if breach was result of third-party service provider failure
  • Investigate if data is accessible/usable (e.g., encrypted)
  • Identify/counsel/verify initial remediation actions taken to immediately limit damage of incident and stop breach
  • Analyze compromised data and determine type(s): PII, PHI, PCI; employee or consumer information
  • Assess number and geographic distribution of potentially affected individuals
  • Identify and assess short-term reporting and regulatory obligations (e.g., HIPAA breach)
  • Counsel on timing of scope of notices
  • Ensure necessary third-party providers are in place
  • Counsel on preservation of evidence (e.g., capturing logs that would ordinarily be deleted)

DELIVERABLE #1: Initial assessment of potential reporting/notification requirements (legal analysis)

Third-Party Provider Assessment

  • Identify third-party service providers
  • Identify relevant insurance coverage
  • Review with internal risk management personnel relevant insurance contracts/coverage
  • Ensure appropriate insurance providers are involved
  • Review relevant services/IT agreements and breach provisions; provide initial advice on next steps/remedies

Identification of External Resources/Service Providers

  • Initiate retention of notice fulfillment services provider as appropriate
  • Retain forensic resources as necessary
  • Retain crisis communications consultant/coordinate with company PR and investor relations teams

DELIVERABLE #2: Ensure necessary third-party providers are in place

DELIVERABLE #3: Prepare forms or provide notice templates specific to location/jurisdiction/regulatory requirements


If your organization has suffered a data breach or incident, contact us at any time (24/7) at at DataBreachResponse@ThompsonHine.com.  A Thompson Hine cybersecurity attorney will respond to you as soon as possible.


For more information about the critical steps following a data breach, please contact:

Thomas F. Zych, Partner, Chair, Privacy & Cybersecurity
216.566.5605
Tom.Zych@ThompsonHine.com

Steven G. Stransky*, Partner, Vice Chair, Privacy & Cybersecurity
202.263.4126 | 216.566.5646
Steve.Stransky@ThompsonHine.com
*International Association of Privacy Professionals, Certified Information Privacy Professional/Government (CIPP/G), Certified Information Privacy Professional/United States (CIPP/US)