HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Jeff Anderson & Associates PA
bd_116d30fdd32f2efd · schema v1 · pii pii-v1
Full breach record for Jeff Anderson & Associates PA →Jeff Anderson & Associates PA reported a data incident where an unauthorized party gained access to computer systems on September 18, 2025, via a vulnerability in firewall protection technology. The attacker copied certain data. The firm detected suspicious activity in September 2025. No evidence of public disclosure or misuse exists. Affected individuals are offered 24 months of credit monitoring.
California clockDiscovered Sep 1, 2025 → Notified Feb 26, 2026178d ✗ CA 60-day late25 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_685ea336212807caVermont State AGfiled 2026-02-26Verified
- bd_4d61d64c2f99c415California State AGfiled 2026-02-10(16d gap)Verified
- bd_17b24dde1fc4edb5Indiana State AGfiled 2025-12-19(69d gap)Candidate
- bd_91b364a07fe72e9cNew Hampshire State AGfiled 2025-12-19(69d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-619384
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 26, 2026
- Raw hash
- 6c8356c19dfba8091dff1bb04c2e6984f7c974d47f29fb8d4044d4e6e163efe4
Reporting entity
- Name
- Jeff Anderson & Associates PAnorm: jeff anderson associates
- Domain
- andersonsadvocates.com
Victim entity
- Name
- Jeff Anderson & Associates PAnorm: jeff anderson associates
- Domain
- andersonsadvocates.com
Incident
- Discovered
- Sep 1, 2025
- Materiality determined
- —
- Notification sent
- Feb 26, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 weeks(178 days from discovery to filing)
- Compliance flags
- CA 60-day late · 178dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 1, 2025→ Notified: Feb 26, 2026178d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Feb 26, 2026→ AG copy submitted: Feb 26, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.