HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICLowContained
Ciuni & Panichi, Inc.
bd_02dd825dcf7a08bb · schema v1 · pii pii-v1
Full breach record for Ciuni & Panichi, Inc. →Ciuni & Panichi, Inc., an accounting services provider, notified the California Attorney General of a data breach affecting client information. On November 3, 2024, the company detected unauthorized activity in an employee email account. The unauthorized access occurred between October 28 and November 4, 2024. The compromised data included names and potentially other personal information. The company secured the account, engaged forensic investigators, reset passwords, and is offering 12 months of credit monitoring to affected individuals.
California clockDiscovered Nov 3, 2024 → Notified Mar 27, 2025144d ✗ CA 60-day late21 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_53b3236f854c20e2New Hampshire State AGfiled 2025-03-31Verified
- bd_5ca7a79c98fd9f23Montana State AGfiled 2025-03-31Verified
- bd_640be21f792d0bfaVermont State AGfiled 2025-03-31Verified
- bd_8b4325ea276de713Maine State AGfiled 2025-03-31Candidate
Show 2 more filings ↓Show fewer ↑up to 28d gap
- bd_f1ffd312c6bd8cacIndiana State AGfiled 2025-03-27(4d gap)Verified
- bd_574e5113ec6f92b4Oregon State AGfiled 2025-04-28(28d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-600657
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 31, 2025
- Raw hash
- c1a250abd86ccc49b0253b2c2013ce2862d6cc5e3d5056e67ebbd9173714a222
Reporting entity
- Name
- Ciuni & Panichi, Inc.norm: ciuni panichi
Victim entity
- Name
- Ciuni & Panichi, Inc.norm: ciuni panichi
Incident
- Discovered
- Nov 3, 2024
- Materiality determined
- —
- Notification sent
- Mar 27, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 21 weeks(148 days from discovery to filing)
- Compliance flags
- CA 60-day late · 144d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 3, 2024→ Notified: Mar 27, 2025144d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.