HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
ATLAS CPAs & Advisors
bd_020ab79d92d82a03 · schema v1 · pii pii-v1
Full breach record for ATLAS CPAs & Advisors →ATLAS CPAs and Advisors PLLC disclosed a security incident discovered on December 10, 2024, involving unauthorized access by an external threat actor. The actor used valid credentials to access systems and exfiltrated files containing Social Security numbers and financial account information. The breach affected 3 Maryland residents. ATLAS engaged forensic experts, notified law enforcement, reset credentials, and offered 12 months of credit monitoring via Experian. Notification to residents was expected by March 24, 2025.
Leak gap clock✗ Leak >180d17 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
A leak claim by silentransomgroup about this victim predates this filing by 463 days.View originating leak claim
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376724.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- f4756859df0f529084a16790626af092a29a455cf49bdec56504467940961aaa
Reporting entity
- Name
- TAFT STETTINIUS & HOLLISTER LLPnorm: taft stettinius hollister
- Domain
- taftlaw.com
Victim entity
- Name
- ATLAS CPAs & Advisorsnorm: atlas cpas advisors
- Domain
- atlascpas.com
Incident
- Discovered
- Dec 10, 2024
- Materiality determined
- —
- Notification sent
- Mar 24, 2025
- Affected individuals
- 3
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified applicable authorities and the IRS
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 months(499 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.