DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors

Posted on May 11, 2025 by Dissent

Daniel Payne reports:

The U.S. Department of Justice says a recent data breach of a California consulting firm exposed data of Catholic clergy abuse survivors in nearly a dozen bankruptcy lawsuits.

In a May 6 letter addressed to attorneys at law firm Proskauer Rose LLP, the Justice Department’s Nan Eitel, the associate general counsel for Chapter 11 practice in the Executive Office for United States Trustees, said that late last month multiple government trustees received notice of a data breach at Berkeley Research Group (BRG).

The Emeryville, California-based BRG offers corporate finance and economic consulting, including to Catholic dioceses in bankruptcy proceedings. The government’s letter said the data breach had occurred on March 2 but that trustees were only first informed on April 28.

Read more at Catholic News Agency.

On March 6, Bloomberg reported that BRG had suffered a cyberattack:

Berkeley Research Group suffered a cyberattack last week, according to people with knowledge of the matter, just as banks have been looking to wrap up a debt sale that would finance the consulting firm’s buyout by TowerBrook Capital Partners.

The firm discovered its systems had been breached on March 2, and received several ransomware notices from a hacker, according to the people, who asked not to be identified discussing a private transaction. The hacker claimed they had taken data from BRG’s systems and had encrypted files within its network, the people added.

BRG has hired data-security firm Octillo Law as well as Booz Allen Hamilton Inc.’s cyber team to deal with the breach, according to a notice sent to the company’s prospective loan investors and seen by Bloomberg News.

But while Bloomberg reported the news, it seems that BRG wasn’t notifying its clients promptly, with some claiming that they were not notified until April 28.

No ransomware gang has publicly claimed responsibility for this attack, and reading the government’s letter to Proskauer Rose, it seems clear that the government is very concerned about — and unhappy with — BRG’s incident response. Reporting by WSJ this week indicates the Proskauer Rose is representing the firm in court.

WSJ‘s report provides some additional details on the attack:

In its notification letters, BRG said the hacker accessed the data by posing as an internal IT worker on Microsoft Teams to log on to a worker’s laptop. Once inside the system, the hacker deployed a variant of Chaos ransomware and demanded payment in return for deleting stolen data, the firm said.

The firm said it paid the hacker an undisclosed amount.

After the payment was made, the hacker provided a “destruction log” and stated that any data gathered in the attack “has since been deleted and will not be disclosed further,” BRG said. To date, the firm said, it has “not detected any evidence of the distribution of any implicated materials.”

As always, DataBreaches reminds people that a criminal’s claims of data destruction should not be believed.

Read more at WSJ.

Category: Business SectorMalwareOf NoteU.S.

Post navigation

← Masimo Manufacturing Facilities Hit by Cyberattack
N.W.T.’s medical record system under the microscope after 2 reported cases of snooping →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • McLaren provides written notice to 743,131 patients after ransomware attack in July 2024
  • A state forensics lab was leaking its files. Getting it locked down involved a number of people.
  • CoinMarketCap Hacked, Scrambles to Remove Malicious Wallet Verification Popup
  • Montana Attorney General launches investigation into Lee Enterprises data breach
  • AT&T gets preliminary approval for $177 million data breach settlement
  • Aflac notifies SEC of breach suspected to be work of Scattered Spider
  • Former JBLM soldier pleads guilty to attempting to share military secrets with China
  • No, the 16 billion credentials leak is not a new data breach — a wake-up call about fake news (Updated)
  • Tonga’s health system hit by cyberattack (1)
  • Russia Expert Falls Prey to Elite Hackers Disguised as US Officials

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The Markup caught 4 more states sharing personal health data with Big Tech
  • Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
  • UK Passes Data Use and Access Regulation Bill
  • Officials defend Liberal bill that would force hospitals, banks, hotels to hand over data
  • US Judge Invalidates Biden Rule Protecting Privacy for Abortions
  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities
  • 23andMe fined £2.31 million for failing to protect UK users’ genetic data

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.