HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Friedman & Perry, CPA's
bd_05beb523b71b294f · schema v1 · pii pii-v1
Full breach record for Friedman & Perry, CPA's →Friedman & Perry, CPA's disclosed a data breach involving unauthorized access via Remote Desktop Protocol (RDP) from a foreign IP address between June 15, 2016, and January 30, 2017. The incident exposed client PII, including SSNs, DOBs, and financial account details. The firm engaged forensic investigators, notified the FBI, IRS, and state agencies, rebuilt its IT infrastructure, and provided 12 months of identity protection services to affected individuals.
California clockDiscovered Feb 6, 2017 → Notified Feb 17, 201711d ✓ CA 60-day OK4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_89995c525614d536Montana State AGfiled 2017-03-09(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-66802
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 8, 2017
- Raw hash
- 9aba35de906c3e647d910c3e73ca47f3c23fddf035374da501277a16e551fb6a
Reporting entity
- Name
- Friedman & Perry, CPA'snorm: friedman perry cpa s
Victim entity
- Name
- Friedman & Perry, CPA'snorm: friedman perry cpa s
Incident
- Discovered
- Feb 6, 2017
- Materiality determined
- —
- Notification sent
- Feb 17, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBINotified the IRSNotified the FTBNotified applicable state agencies
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 11d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 6, 2017→ Notified: Feb 17, 201711d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.