HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICPIILowContained
GRANT THORNTON LLP
bd_17cad5b1f2afa8e1 · schema v1 · pii pii-v1
Full breach record for GRANT THORNTON LLP →Grant Thornton LLP reported that an unauthorized third party gained access to an employee's email account between April 19, 2023, and May 1, 2023. The incident was discovered on May 1, 2023. Affected data included names and other personal information. Grant Thornton engaged a forensic firm, implemented additional technical controls, and offered one year of identity monitoring services via Kroll.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_618fec45c9ed840cMaine State AGfiled 2023-09-19Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-573889
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 19, 2023
- Raw hash
- a36590359c41eb7cbdbff1b2a3df5ba068d69c1fc8af625358fbf9c8f3ba1057
Reporting entity
- Name
- GRANT THORNTON LLPnorm: grant thornton
Victim entity
- Name
- GRANT THORNTON LLPnorm: grant thornton
Incident
- Discovered
- May 1, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
Compliance
- Time to disclose
- 20 weeks(141 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.