Social EngineeringPhishingCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Next Peak CPA
bd_292396f43ba8ad28 · schema v1 · pii pii-v1
Full breach record for Next Peak CPA →Next Peak CPA, Inc. reported a security incident in California where an unauthorized individual accessed an employee's email account between Feb 18-19, 2021. The breach exposed customer PII, including Social Security numbers and names. The company engaged outside cybersecurity professionals, investigated the compromise, and offered one year of complimentary credit monitoring via Experian IdentityWorks to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-547711
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 18, 2021
- Raw hash
- 4eb2ce137b28c74b85291429c0de5e21f2d64e328c78d36b08aa81e43ac6307b
Reporting entity
- Name
- Next Peak CPAnorm: next peak cpa
- Domain
- nextpeakcpa.com
Victim entity
- Name
- Next Peak CPAnorm: next peak cpa
- Domain
- nextpeakcpa.com
Incident
- Discovered
- Feb 19, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 39 weeks(272 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.