Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchThe incident was a real 2023 cyberattack, but it was not publicly reported as a breach of the U.S. Department of Justice’s own network. Hackers breached Greylock McKinnon Associates (GMA), a private litigation-support firm that held DOJ-originated information. Maine records say information affecting 341,650 people was involved, including Social Security numbers contained within Medicare Health Insurance Claim Numbers.
The breach occurred on May 30, 2023, was discovered on February 7, 2024, and notices were mailed in April 2024. The available public record does not establish who carried out the attack, whether the data was published or sold, or whether it was used for identity theft.
The short version
- Company breached: Greylock McKinnon Associates Inc., a Boston-based economic-analysis and litigation-support firm.
- People affected: 341,650, including 2,067 Maine residents listed in the state filing.
- Breach date: May 30, 2023.
- Discovery date: February 7, 2024.
- Notification date: April 5, 2024, with the individual notice dated April 8.
- Information involved: Names and other identifiers, dates of birth, addresses, Medicare information, some medical or health-insurance information, and Social Security numbers contained in Medicare claim numbers.
- Confirmed misuse: None established in the public records reviewed.
The official Maine filing classifies the incident as an external-system breach, or hacking. A later proposed class-action complaint reportedly described it as ransomware, but that remains a litigation allegation rather than an attack type confirmed in the official breach filing. Maine Attorney General records and GMA’s consumer notice are the primary sources for these details.
What Greylock McKinnon Associates does
GMA is a consulting firm with offices listed in Boston, Washington, D.C., and Hanover, New Hampshire. Its work includes economic analysis and litigation support for legal, business, government, and civil-litigation clients.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
The DOJ-related data was held by GMA because the Justice Department had obtained it as part of a civil-litigation matter and transferred it to the firm for litigation-support work. The public notices do not identify that litigation or explain why each person’s information was collected.
GMA’s notice says the DOJ advised that the people notified were not subjects of the investigation or associated litigation. That means an affected person could have had information in the file without ever dealing directly with GMA or being accused of wrongdoing.
Was the DOJ hacked?
The available evidence supports describing this as a breach at a DOJ service provider, not a confirmed compromise of DOJ infrastructure.
A precise description is: “Hackers breached Greylock McKinnon Associates, a private litigation-support firm that held information supplied by the Justice Department.” It would overstate the evidence to say that hackers breached the DOJ and stole 340,000 Social Security numbers directly from a government network.
What information was exposed?
GMA’s notice uses qualified language such as “may have included” and “likely affected.” It does not establish that every person had every listed data element exposed. The categories may have included:
- Name and other personal identifiers
- Date of birth
- Home address
- Medicare Health Insurance Claim Number
- A Social Security number contained within that Medicare claim number
- Some medical information
- Health-insurance information
The important Social Security number qualification
Headlines commonly summarize the incident as involving 340,000 stolen Social Security numbers. That is broadly understandable but incomplete. The Maine filing says the Social Security numbers were included within Medicare Health Insurance Claim Numbers, rather than necessarily being exposed as standalone Social Security number fields.
The more accurate description is that information affecting 341,650 people included Medicare-linked records containing Social Security numbers. The public filing does not support saying that precisely 341,650 standalone Social Security numbers were stolen.
Timeline: from attack to notification
| Date | What happened |
|---|---|
| May 30, 2023 | GMA experienced the reported cyberattack or detected the relevant unusual activity. |
| February 7, 2024 | The Maine filing identifies this as the discovery date for the DOJ-related affected population. |
| April 5, 2024 | GMA’s notices were mailed, according to the Maine record. |
| April 8, 2024 | Date shown on the individual consumer notice; prominent news coverage also appeared around this date. |
| May 31, 2024 | A proposed class action was reported as filed in the U.S. District Court for the District of Massachusetts. |
GMA said it engaged cybersecurity specialists, notified law enforcement and the DOJ, investigated the affected systems and data, and worked to identify affected people and obtain their addresses. The public notice does not fully explain why the May 2023 incident was not disclosed until April 2024. That delay is a legitimate reporting question, but it is not by itself proof of misconduct.
What GMA offered affected people
For the DOJ-related population, the Maine filing and consumer notice describe 24 months of single-bureau credit monitoring, access to a credit report and score, alerts for changes to the monitored file, and proactive fraud assistance and remediation. The service was identified as Cyberscout, using services associated with IdentityForce and TransUnion.
“Single-bureau” matters: the offer should not automatically be understood as monitoring all three nationwide credit reports. Read the enrollment terms in the letter you received.
GMA also said it deleted DOJ data from its systems after the incident. Other GMA notices involved different populations, information, vendors, and protection periods. For example, separate Massachusetts filings describe other incidents and Experian IdentityWorks offers. Do not enroll through a different GMA notice unless your own letter identifies that service. See the Massachusetts filing for one separate GMA notice and the filing for another.
What affected people should do now
1. Verify and use the official notice
If you received a letter, use only the enrollment instructions and deadline printed there. Save the letter, enrollment confirmation, service terms, and monitoring alerts. A complimentary breach service should not require payment-card information merely to activate the benefit.
Recommended Free Tools
Confirm that your letter concerns the DOJ-related incident. GMA notified other groups about separate incidents, so the exposed information and monitoring provider may differ. If someone contacts you unexpectedly claiming to represent GMA, the DOJ, Medicare, or a monitoring company, verify the organization independently and do not use links or phone numbers supplied in an unsolicited message.
2. Freeze all three credit reports
A credit freeze is generally more protective against new-account fraud than monitoring alone. Monitoring alerts you to certain activity; a freeze restricts access to your credit report until you temporarily lift it.
Place freezes separately with all three nationwide consumer-reporting agencies:
A freeze does not prevent every form of identity theft. It will not by itself stop takeover of an existing account, medical-identity misuse, tax fraud, phishing, or scams using exposed personal details.
3. Consider a fraud alert
A fraud alert asks creditors to take additional steps to verify your identity. It is less restrictive than a freeze and should not be treated as a replacement for freezing all three reports when you are concerned about SSN-linked information.
The Federal Trade Commission’s IdentityTheft.gov service provides free recovery guidance if you find evidence of fraud.
4. Protect tax filings
An IRS Identity Protection PIN can help prevent someone from filing a fraudulent federal tax return using your information. It is useful but narrow: it does not protect credit accounts, bank accounts, or medical records.
5. Review existing accounts and records
- Bank and credit-card statements
- Credit reports and unfamiliar inquiries
- Medicare account activity and Explanation of Benefits notices
- Insurance Explanation of Benefits documents
- Unexpected collection notices
- IRS correspondence
- Accounts where a reused password may be exposed
Contact banks, insurers, Medicare, credit bureaus, or other institutions through verified contact information if you see suspicious activity.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
Was the data used for identity theft?
The sources reviewed do not establish confirmed identity theft or fraud resulting from this incident. GMA’s offer of monitoring and fraud assistance is a precaution and does not prove that the information was misused.
The public record also does not establish who conducted the attack, how the attackers entered GMA’s systems, whether the information was posted or sold, or whether a specific threat group was responsible.
Lawsuit and later developments
A proposed class action reported in May 2024 alleged that GMA failed to adequately protect personal information and characterized the incident as ransomware. Those are allegations, not adjudicated findings. The existence of a lawsuit does not establish liability.
GMA maintains a litigation documents page. Any claim about a later settlement, payment, claims deadline, or final court ruling should be checked against current court documents rather than inferred from the original breach notices.
The broader contractor-security issue
This incident illustrates a third-party risk problem: sensitive information collected or held by a government agency may be processed by a private contractor whose systems become the target.
For government and regulated organizations, the practical questions include whether contracts require encryption, separate client environments, access controls, retention limits, secure deletion, audits, and rapid incident reporting. The public materials reviewed do not establish whether GMA violated a particular federal contract or security standard, so those questions should not be turned into unsupported conclusions.
For affected individuals, the key point is simpler: never assume that a government-related data notice means the government’s own network was breached, and never assume that a monitoring subscription eliminates the need for free credit freezes and account vigilance.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors




