DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors

Posted on May 11, 2025 by Dissent

Daniel Payne reports:

The U.S. Department of Justice says a recent data breach of a California consulting firm exposed data of Catholic clergy abuse survivors in nearly a dozen bankruptcy lawsuits.

In a May 6 letter addressed to attorneys at law firm Proskauer Rose LLP, the Justice Department’s Nan Eitel, the associate general counsel for Chapter 11 practice in the Executive Office for United States Trustees, said that late last month multiple government trustees received notice of a data breach at Berkeley Research Group (BRG).

The Emeryville, California-based BRG offers corporate finance and economic consulting, including to Catholic dioceses in bankruptcy proceedings. The government’s letter said the data breach had occurred on March 2 but that trustees were only first informed on April 28.

Read more at Catholic News Agency.

On March 6, Bloomberg reported that BRG had suffered a cyberattack:

Berkeley Research Group suffered a cyberattack last week, according to people with knowledge of the matter, just as banks have been looking to wrap up a debt sale that would finance the consulting firm’s buyout by TowerBrook Capital Partners.

The firm discovered its systems had been breached on March 2, and received several ransomware notices from a hacker, according to the people, who asked not to be identified discussing a private transaction. The hacker claimed they had taken data from BRG’s systems and had encrypted files within its network, the people added.

BRG has hired data-security firm Octillo Law as well as Booz Allen Hamilton Inc.’s cyber team to deal with the breach, according to a notice sent to the company’s prospective loan investors and seen by Bloomberg News.

But while Bloomberg reported the news, it seems that BRG wasn’t notifying its clients promptly, with some claiming that they were not notified until April 28.

No ransomware gang has publicly claimed responsibility for this attack, and reading the government’s letter to Proskauer Rose, it seems clear that the government is very concerned about — and unhappy with — BRG’s incident response. Reporting by WSJ this week indicates the Proskauer Rose is representing the firm in court.

WSJ‘s report provides some additional details on the attack:

In its notification letters, BRG said the hacker accessed the data by posing as an internal IT worker on Microsoft Teams to log on to a worker’s laptop. Once inside the system, the hacker deployed a variant of Chaos ransomware and demanded payment in return for deleting stolen data, the firm said.

The firm said it paid the hacker an undisclosed amount.

After the payment was made, the hacker provided a “destruction log” and stated that any data gathered in the attack “has since been deleted and will not be disclosed further,” BRG said. To date, the firm said, it has “not detected any evidence of the distribution of any implicated materials.”

As always, DataBreaches reminds people that a criminal’s claims of data destruction should not be believed.

Read more at WSJ.


Related:

  • Will Beacon Health Solutions' incident prompt OCR to start enforcing notification "without undue delay?"
  • Protect Good Faith Security Research Globally in Proposed UN Cybercrime Treaty
  • The Secret IRS Files: Trove of Never-Before-Seen Records Reveal How the Wealthiest Avoid Income Tax
  • Man who hacked St. Louis County police union gets 18 months
  • Kept in the Dark -- Meet the Hired Guns Who Make Sure School Cyberattacks Stay Hidden
Category: Business SectorMalwareOf NoteU.S.

Post navigation

← Masimo Manufacturing Facilities Hit by Cyberattack
N.W.T.’s medical record system under the microscope after 2 reported cases of snooping →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • 45,000 malicious IP addresses taken down in international cyber operation
  • The Broken Records: tracing the human cost of the 2022 British MoD leak
  • Telus Digital confirms breach after ShinyHunters claims 1 petabyte data theft
  • China’s CERT warns OpenClaw can inflict nasty wounds
  • Bell Ambulance data breach impacted over 238,000 people
  • Lotte Card fined 9.6 billion won for leaking users’ social registration numbers
  • Handala claims responsibility for attack on medical device maker Stryker
  • Police Scotland fined £66k for extracting and sharing mobile phone data
  • The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in life
  • Viral ‘Quittr’ Porn Addiction App Exposed the Masturbation Habits of Hundreds of Thousands of Users

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • New data shows increase in FBI searches of Americans’ data last year
  • CalPrivacy Fines PlayOn Sports $1.1 Million for CCPA Violations Involving Student Privacy
  • 17 States Sues Trump Administration Over Unlawful Data Demands Targeting Colleges
  • Privacy watchdogs sound alarm over US bid to get travellers’ social media
  • Petition filed over misuse of protesters’ data by Kenyan government and telcos

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: Dissent.73

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.