HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Douglas M Smith & Co, CPAs
bd_3262bcf5a826e53f · schema v1 · pii pii-v1
Full breach record for Douglas M Smith & Co, CPAs →Douglas M Smith & Co, CPAs discovered on February 23, 2026, that an unauthorized user accessed their third-party tax filing software to file fraudulent tax returns. The breach occurred on January 20, 2026. Affected data includes Social Security numbers, government IDs, names, and bank account information. The firm notified law enforcement (FBI, Secret Service, IRS, FTC) and is offering 12 months of credit monitoring. No mass data exfiltration was indicated.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-621806
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 15, 2026
- Raw hash
- 46a969c10b643f0f8d072ed552b168d78c386edadf59fca51b660440b94b4221
Reporting entity
- Name
- Douglas M Smith & Co, CPAsnorm: douglas m smith co cpas
Victim entity
- Name
- Douglas M Smith & Co, CPAsnorm: douglas m smith co cpas
Incident
- Discovered
- Feb 23, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FTC, FBI, IRS, and Secret Service
- Third party
- via Third-party tax filing software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.