HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
MSA Accounting CPA, Professional Corp.
bd_040c1f3170e56d15 · schema v1 · pii pii-v1
Full breach record for MSA Accounting CPA, Professional Corp. →MSA Accounting, a California CPA firm, reported suspicious IRS activity involving unauthorized 2016 tax filings by clients. Forensic investigation found no network breach, but client data (PII, SSN, financial info) was potentially accessed via compromised credentials. The firm notified the FBI and IRS, changed passwords, and offered credit monitoring guidance.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-67943
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 2, 2017
- Raw hash
- 63efa5d6b291e3ee9f84c72a68b44f9a1bc82b2b25c23dd82d326b7313494c0e
Reporting entity
- Name
- MSA Accounting CPA, Professional Corp.norm: msa accounting cpa professional
Victim entity
- Name
- MSA Accounting CPA, Professional Corp.norm: msa accounting cpa professional
Incident
- Discovered
- Apr 11, 2017
- Materiality determined
- Apr 11, 2017
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.