HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICEMPLOYMENTLowContained
Woodruff Sawyer & Co.
bd_05d436bb4d52abd6 · schema v1 · pii pii-v1
Full breach record for Woodruff Sawyer & Co. →Woodruff Sawyer & Co. disclosed unauthorized access to employee email accounts between March 2 and April 30, 2020. The incident involved potential exposure of personal information for clients and employees. The company engaged forensic investigators, reset passwords, and is offering credit monitoring services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3becb4dbc41e6135Oregon State AGfiled 2020-11-12(26d gap)Verified by operator
- bd_d237dca2559a135fWashington State AGfiled 2020-11-10(28d gap)Verified
- bd_a4ee49c5e2e7c8d2Montana State AGfiled 2020-11-09(29d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-196912
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 8, 2020
- Raw hash
- 58f8a47f2da33bd1532f22a5a10c3a6ec7d57c4e174d767d7ca553c57ae128e1
Reporting entity
- Name
- Woodruff Sawyer & Co.norm: woodruff sawyer
- Domain
- woodruffsawyer.com
Victim entity
- Name
- Woodruff Sawyer & Co.norm: woodruff sawyer
- Domain
- woodruffsawyer.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Sep 1, 2020
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notifying state and federal regulators, as required
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.