MalwareData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Creal & Creal, An Accountancy Corporation
bd_1cb3cb41916a2845 · schema v1 · pii pii-v1
Full breach record for Creal & Creal, An Accountancy Corporation →Creal & Creal, An Accountancy Corporation experienced a data breach involving malware that gained access to a server on September 10, 2020. The incident was discovered on October 8, 2020, when IRS e-file rejections were received. Compromised data included names, addresses, SSNs, bank account information, dates of birth, and driver's license numbers. The firm engaged forensic investigators, deleted the malware, implemented ESET anti-virus, and offered 24 months of identity monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-198339
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 8, 2021
- Raw hash
- 938b1a60925e88fff5cdc006a1f564d7a8d23bc25571945f4f08095ef5fa2463
Reporting entity
- Name
- Creal & Creal, An Accountancy Corporationnorm: creal creal an accountancy
Victim entity
- Name
- Creal & Creal, An Accountancy Corporationnorm: creal creal an accountancy
Incident
- Discovered
- Oct 8, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Contacted the Internal Revenue Service
Compliance
- Time to disclose
- 13 weeks(92 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.