HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
BMB Associates, Inc.
bd_17ec42e8cf2d9fc6 · schema v1 · pii pii-v1
Full breach record for BMB Associates, Inc. →BMB Associates discovered unauthorized access to its Intuit ProSeries service on March 16, 2020, when IRS e-file rejections indicated fraudulent tax filings by a third party who created a guest account. The attacker potentially accessed names, addresses, SSNs, and financial account information. The company removed the account, changed passwords, and notified law enforcement and the IRS. Identity theft protection was offered to clients.
California clockDiscovered Mar 16, 2020 → Notified Sep 4, 2020172d ✗ CA 60-day late26 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6b2cdea1d29d8f02Maine State AGfiled 2020-09-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-194051
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2020
- Raw hash
- 855741bb1a88e3518fa30d606569b0d2cf8aa019478d3bdf6f893e03cd07822c
Reporting entity
- Name
- BMB Associates, Inc.norm: bmb associates
- Domain
- bmbassociates.com
Victim entity
- Name
- BMB Associates, Inc.norm: bmb associates
- Domain
- bmbassociates.com
Incident
- Discovered
- Mar 16, 2020
- Materiality determined
- —
- Notification sent
- Sep 4, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to the Sacramento Valley Hi-Tech Crimes UnitReported the incident to the Federal Bureau of Investigation (FBI)Reported the incident to the Internal Revenue Service (IRS)
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 weeks(183 days from discovery to filing)
- Compliance flags
- CA 60-day late · 172d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 16, 2020→ Notified: Sep 4, 2020172d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.