Company Details
prime-clerk
63
1,444
5411
kroll.com
0
PRI_5703854
In-progress

Prime Clerk Company CyberSecurity Posture
kroll.comPrime Clerk is a legal technology company providing comprehensive claims administration, case management, noticing, solicitation and consulting services to companies, their attorneys and financial advisors. We offer effective and efficient technology-based solutions for restructuring cases, whether inside or outside of bankruptcy. A New Level of Transparency Prime Clerk believes that continuous information flow is vital to our clients’ understanding of the services we provide. Clients have real time access to graphics and analytics measuring all the tasks and responsibilities Prime Clerk is handling on their behalf. The result is seamless online review and communication, leading to enhanced productivity and fewer conversations to distract professionals. Heightened Accountability & Professionalism Prime Clerk holds itself to a higher standard. Never before has a more experienced team of restructuring attorneys and consultants come together in this industry with the sole focus of providing the highest quality work and most practical solutions. As an independent organization focused solely on bankruptcy administration, we answer only to our clients and deliver the fastest, smartest and best results. Unparalleled Client Access Prime Clerk provides intuitive access to all information associated with a case, allowing the user to review notice records, claim data, real time balloting results and disbursement details. Clients can design customized reports and direct them for delivery to multiple parties on a one-time or recurring basis. Maximizing Technology We built the first all-encompassing bankruptcy administration system. Unlike competing industry platforms, which still require manual data input and processing, all elements of Prime Clerk are integrated and driven by our dynamic, proprietary software. For Prime Clerk clients, the result is increased efficiency, greater reliability and reduced costs.
Company Details
prime-clerk
63
1,444
5411
kroll.com
0
PRI_5703854
In-progress
Between 750 and 799

Prime Clerk Global Score (TPRM)XXXX

Description: Honig’s Whistle Stop, Inc. suffered a data breach in which unauthorized actors accessed sensitive customer information, including names and credit card details. The incident was officially confirmed on **April 9, 2015**, though the exact number of affected individuals remains undisclosed. The breach exposed customers to potential financial fraud and identity theft risks. In response, the company implemented enhanced security measures to prevent future incidents and partnered with **Kroll** to provide **one year of free identity theft protection services** to impacted customers. The breach underscores vulnerabilities in the organization’s data protection protocols, particularly concerning payment card security, and highlights the broader risks of financial fraud and reputational damage stemming from such incidents.
Description: The SIM-swapping attack on one of Kroll's workers resulted in the loss of user information for several cryptocurrency sites, the security consulting firm Kroll disclosed. For the affected companies, including BlockFi, FTX, and Genesis, Kroll is in charge of the ongoing bankruptcy processes. Data on specific people may have been exposed due to the security incident Kroll experienced. In phishing assaults, threat actors may already be attempting to make use of the stolen data, according to the media. The SIM swap against the Kroll employee has the unintended effect of revealing anyone who has a business connection with BlockFi, FTX, or Genesis.


No incidents recorded for Prime Clerk in 2025.
No incidents recorded for Prime Clerk in 2025.
No incidents recorded for Prime Clerk in 2025.
Prime Clerk cyber incidents detection timeline including parent company and subsidiaries

Prime Clerk is a legal technology company providing comprehensive claims administration, case management, noticing, solicitation and consulting services to companies, their attorneys and financial advisors. We offer effective and efficient technology-based solutions for restructuring cases, whether inside or outside of bankruptcy. A New Level of Transparency Prime Clerk believes that continuous information flow is vital to our clients’ understanding of the services we provide. Clients have real time access to graphics and analytics measuring all the tasks and responsibilities Prime Clerk is handling on their behalf. The result is seamless online review and communication, leading to enhanced productivity and fewer conversations to distract professionals. Heightened Accountability & Professionalism Prime Clerk holds itself to a higher standard. Never before has a more experienced team of restructuring attorneys and consultants come together in this industry with the sole focus of providing the highest quality work and most practical solutions. As an independent organization focused solely on bankruptcy administration, we answer only to our clients and deliver the fastest, smartest and best results. Unparalleled Client Access Prime Clerk provides intuitive access to all information associated with a case, allowing the user to review notice records, claim data, real time balloting results and disbursement details. Clients can design customized reports and direct them for delivery to multiple parties on a one-time or recurring basis. Maximizing Technology We built the first all-encompassing bankruptcy administration system. Unlike competing industry platforms, which still require manual data input and processing, all elements of Prime Clerk are integrated and driven by our dynamic, proprietary software. For Prime Clerk clients, the result is increased efficiency, greater reliability and reduced costs.

Edward Jones is a leading North American financial services firm in the U.S. and through its affiliate in Canada. The firm’s more than 20,000 financial advisors throughout North America serve more than 9 million clients with a total of $2.2 trillion in client assets under care as of December 31, 202

As a global leader in innovative wealth management, asset servicing and investment solutions, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families and institutions by remaining true to our enduring principles of service, expertise and integrity. A global

We’ve finally given a name to that special something a person exudes when they have a plan for their finances. It’s called The F Factor – and now that you know its name, it’s time you feel it too. Let's unlock your financial confidence, together. Our team is online weekdays 8:30 – 16:00

CIMB Group is a leading ASEAN universal bank, one of the largest Asian investment banks and one of the world's largest Islamic banks. We are headquartered in Kuala Lumpur, Malaysia and offer consumer banking, commercial banking, wholesale banking, Islamic banking, and asset management products and

At Capital One, we're making things better for our customers and associates through innovation and collaboration. We were founded on the belief that everyone deserves financial freedom—and are dedicated to a world where all have equal opportunity to prosper. Banking is in our DNA, but we are so mu

We provide employee, financial and legal administration so that firms can invest and operate safely around the world. TMF Group is a single global team with over 11,000 colleagues in more than 125 offices across 87 jurisdictions, covering 92% of world GDP and 95% of FDI inflow. We bring common c
.png)
Kroll has further unified its global brand, with Prime Clerk and Lucid Companies both retiring their own corporate identities.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Prime Clerk is https://www.kroll.com/en/services/restructuring-administration.
According to Rankiteo, Prime Clerk’s AI-generated cybersecurity score is 751, reflecting their Fair security posture.
According to Rankiteo, Prime Clerk currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Prime Clerk is not certified under SOC 2 Type 1.
According to Rankiteo, Prime Clerk does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Prime Clerk is not listed as GDPR compliant.
According to Rankiteo, Prime Clerk does not currently maintain PCI DSS compliance.
According to Rankiteo, Prime Clerk is not compliant with HIPAA regulations.
According to Rankiteo,Prime Clerk is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Prime Clerk operates primarily in the Legal Services industry.
Prime Clerk employs approximately 63 people worldwide.
Prime Clerk presently has no subsidiaries across any sectors.
Prime Clerk’s official LinkedIn profile has approximately 1,444 followers.
Prime Clerk is classified under the NAICS code 5411, which corresponds to Legal Services.
Yes, Prime Clerk has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/prime-clerk.
Yes, Prime Clerk maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/prime-clerk.
As of November 30, 2025, Rankiteo reports that Prime Clerk has experienced 2 cybersecurity incidents.
Prime Clerk has an estimated 7,389 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach and Data Leak.
Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with kroll (identity theft protection services), and remediation measures with enhanced security measures..
Title: SIM-swapping Attack on Kroll Employee
Description: A SIM-swapping attack on a Kroll employee resulted in the loss of user information for several cryptocurrency sites, including BlockFi, FTX, and Genesis.
Type: SIM-swapping
Attack Vector: SIM-swapping
Vulnerability Exploited: SIM-swapping
Motivation: Data Exfiltration
Title: Data Breach at Honig’s Whistle Stop, Inc.
Description: The California Office of the Attorney General reported that Honig’s Whistle Stop, Inc. experienced a data breach affecting personal information, including customer names and credit card details, potentially impacting an unknown number of individuals. The breach was confirmed on April 9, 2015, and the organization took steps to enhance security and offered identity theft protection services through Kroll at no cost for one year.
Date Publicly Disclosed: 2015-04-09
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Breach.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through SIM-swapping.

Data Compromised: User information for several cryptocurrency sites
Identity Theft Risk: ['High']

Data Compromised: Customer names, Credit card details
Identity Theft Risk: High (identity theft protection services offered)
Payment Information Risk: High (credit card details compromised)
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Information, Business Connections, , Personal Information, Payment Information and .

Entity Name: Kroll
Entity Type: Security Consulting Firm
Industry: Security Consulting
Customers Affected: BlockFi, FTX, Genesis

Entity Name: Honig’s Whistle Stop, Inc.
Entity Type: Business
Location: California, USA
Customers Affected: Unknown

Third Party Assistance: Kroll (Identity Theft Protection Services).
Remediation Measures: Enhanced security measures
Third-Party Assistance: The company involves third-party assistance in incident response through Kroll (identity theft protection services), .

Type of Data Compromised: Personal information, Business connections
Sensitivity of Data: High

Type of Data Compromised: Personal information, Payment information
Number of Records Exposed: Unknown
Sensitivity of Data: High
Personally Identifiable Information: customer names
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Enhanced security measures.

Regulatory Notifications: California Office of the Attorney General

Source: California Office of the Attorney General
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney General.

Customer Advisories: Identity theft protection services offered through Kroll for one year at no cost
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was Identity theft protection services offered through Kroll for one year at no cost.

Entry Point: SIM-swapping
High Value Targets: Blockfi, Ftx, Genesis,
Data Sold on Dark Web: Blockfi, Ftx, Genesis,

Root Causes: SIM-swapping attack

Corrective Actions: Enhanced security measures
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Kroll (Identity Theft Protection Services), .
Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Enhanced security measures.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2015-04-09.
Most Significant Data Compromised: The most significant data compromised in an incident were User information for several cryptocurrency sites, , customer names, credit card details and .
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was kroll (identity theft protection services), .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were User information for several cryptocurrency sites, customer names and credit card details.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 0.
Most Recent Source: The most recent source of information about an incident is California Office of the Attorney General.
Most Recent Customer Advisory: The most recent customer advisory issued was an Identity theft protection services offered through Kroll for one year at no cost.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an SIM-swapping.
.png)
A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. Executing manipulation can lead to use of hard-coded cryptographic key . The physical device can be targeted for the attack. A high complexity level is associated with this attack. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files based solely on an authenticated session and user-supplied identifiers, without verifying whether the requester has permission to access the associated interview record. Because the server does not perform any recruitment-level authorization checks, an ESS-level user with no access to recruitment workflows can directly request interview attachment URLs and receive the corresponding files. This exposes confidential interview documents—including candidate CVs, evaluations, and supporting files—to unauthorized users. The issue arises from relying on predictable object identifiers and session presence rather than validating the user’s association with the relevant recruitment process. This issue has been patched in version 5.8.
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitment attachment retrieval endpoint does not enforce the required authorization checks before serving candidate files. Even users restricted to ESS-level access, who have no permission to view the Recruitment module, can directly access candidate attachment URLs. When an authenticated request is made to the attachment endpoint, the system validates the session but does not confirm that the requesting user has the necessary recruitment permissions. As a result, any authenticated user can download CVs and other uploaded documents for arbitrary candidates by issuing direct requests to the attachment endpoint, leading to unauthorized exposure of sensitive applicant data. This issue has been patched in version 5.8.
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when a password change occurs, allowing active session cookies to remain valid indefinitely. As a result, a disabled user, or an attacker using a compromised account, can continue to access protected pages and perform operations as long as a prior session remains active. Because the server performs no session revocation or session-store cleanup during these critical state changes, disabling an account or updating credentials has no effect on already-established sessions. This makes administrative disable actions ineffective and allows unauthorized users to retain full access even after an account is closed or a password is reset, exposing the system to prolonged unauthorized use and significantly increasing the impact of account takeover scenarios. This issue has been patched in version 5.8.
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final reset request matches the account for which the reset process was originally initiated. After obtaining a valid reset link for any account they can receive email for, an attacker can alter the username parameter in the final reset request to target a different user. Because the system accepts the supplied username without verification, the attacker can set a new password for any chosen account, including privileged accounts, resulting in full account takeover. This issue has been patched in version 5.8.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.