HackingData ExfiltratedData PublishedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
Kronick Moskovitz Tiedemann & Girard
bd_26e21b83d173f48c · schema v1 · pii pii-v1
Full breach record for Kronick Moskovitz Tiedemann & Girard →Kronick Moskovitz Tiedemann & Girard, a California law firm, discovered unauthorized access to its network in August 2024. The incident, which occurred on July 19, 2024, involved an unknown third party who exfiltrated data including names, SSNs, DOBs, driver's license numbers, and medical/health insurance information. The attacker temporarily posted the data on a dark web site. The firm disconnected systems, reset credentials, engaged forensic experts, and notified law enforcement. Affected individuals are offered 24 months of Experian credit monitoring.
Leak gap clock✗ Leak >180d43 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (2)
- bd_485be91e1544288fLeak Siterhysidafiled 2024-08-22(280d gap)Verified
- bd_5115b8f34c464313Leak Siterhysidafiled 2024-08-06(297d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_3b9c18091611fea2California State AGfiled 2025-03-28(63d gap)Verified by operator
- bd_78a8971981b2e05cVermont State AGfiled 2025-03-28(63d gap)Verified by operator
- bd_85953c04009ba220Indiana State AGfiled 2025-03-28(63d gap)Verified
- bd_d2db47f3b9d4421fHHS OCRfiled 2025-02-28(91d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 91d gap
- bd_f96d420733a272ebCalifornia State AGfiled 2025-02-28(91d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-603439
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 30, 2025
- Raw hash
- 9df9906fadee982e07bd3d18fc0576ab107bb17c586d7357990631958f9fe6be
Reporting entity
- Name
- Kronick Moskovitz Tiedemann & Girardnorm: kronick moskovitz tiedemann girard
- Domain
- kmtg.com
Victim entity
- Name
- Kronick Moskovitz Tiedemann & Girardnorm: kronick moskovitz tiedemann girard
- Domain
- kmtg.com
Incident
- Discovered
- Aug 1, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 ChannelT1567 Exfiltration Over Web Service
- Threat actor
- External
- Regulator citations
- Notified law enforcement
Compliance
- Time to disclose
- 43 weeks(302 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.