HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSBIOMETRICMediumContained
Keesal, Young & Logan
bd_32aedb4bbecc8bf3 · schema v1 · pii pii-v1
Full breach record for Keesal, Young & Logan →Keesal, Young & Logan experienced unauthorized access to its network between June 7 and June 13, 2024. The firm identified suspicious activity on June 13, 2024, and engaged third-party forensic specialists. The unauthorized actor acquired information including names, SSNs, financial account info, driver's licenses, medical info, and credentials. The firm is offering credit monitoring and identity restoration services.
California clockDiscovered Jun 13, 2024 → Notified Nov 27, 2024167d ✗ CA 60-day late24 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0d913969dcc0919aIndiana State AGfiled 2024-11-27Verified
- bd_22e0ae01c16811a7New Hampshire State AGfiled 2024-11-27Verified
- bd_427bb4afbe50ade2Montana State AGfiled 2024-11-27Candidate
- bd_6cd7715cb023f1c6Maine State AGfiled 2024-11-27Verified by operator
Show 2 more filings ↓Show fewer ↑
- bd_ccf7ffad7258cedcVermont State AGfiled 2024-11-27Verified
- bd_dfd42d621f875298Washington State AGfiled 2024-11-27Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-595481
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 27, 2024
- Raw hash
- 901ecfbca280874e6a090527400ea5b5fa961366642172106d089ac1c2278107
Reporting entity
- Name
- Keesal, Young & Logannorm: keesal young logan
- Domain
- kyl.com
Victim entity
- Name
- Keesal, Young & Logannorm: keesal young logan
- Domain
- kyl.com
Incident
- Discovered
- Jun 13, 2024
- Materiality determined
- —
- Notification sent
- Nov 27, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSBIOMETRIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 24 weeks(167 days from discovery to filing)
- Compliance flags
- CA 60-day late · 167d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 13, 2024→ Notified: Nov 27, 2024167d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.