Kronick Moskovitz Tiedemann & Girard
bd_3b9c18091611fea2 · schema v1 · pii pii-v1
Full breach record for Kronick Moskovitz Tiedemann & Girard →Kronick Moskovitz Tiedemann & Girard, a California law firm, experienced unauthorized access to its network by an unknown third party. The breach occurred on July 19, 2024, and was discovered in August 2024. The attacker exfiltrated data including names, Social Security numbers, dates of birth, driver's license numbers, and medical/health insurance information. The data was temporarily posted on a dark web site. The firm disconnected systems, reset credentials, engaged forensic experts, and notified law enforcement. Affected individuals are offered 24 months of Experian credit monitoring.
Linked disclosures
Why this link?Ransomware claims (2)
- bd_485be91e1544288fLeak Siterhysidafiled 2024-08-22(217d gap)Verified
- bd_5115b8f34c464313Leak Siterhysidafiled 2024-08-06(234d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_78a8971981b2e05cVermont State AGfiled 2025-03-28Verified by operator
- bd_85953c04009ba220Indiana State AGfiled 2025-03-28Verified
- bd_d2db47f3b9d4421fHHS OCRfiled 2025-02-28(28d gap)Verified
- bd_f96d420733a272ebCalifornia State AGfiled 2025-02-28(28d gap)Verified by operator
Show 1 more filing ↓Show fewer ↑up to 63d gap
- bd_26e21b83d173f48cCalifornia State AGfiled 2025-05-30(63d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-600568
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 28, 2025
- Raw hash
- 68bdbb31dbe96d7bb93a7fe3c58a28948fdab5a9dcc62a65f68be0b2042fa346
Reporting entity
- Name
- Kronick Moskovitz Tiedemann & Girardnorm: kronick moskovitz tiedemann girard
- Domain
- kmtg.com
Victim entity
- Name
- Kronick Moskovitz Tiedemann & Girardnorm: kronick moskovitz tiedemann girard
- Domain
- kmtg.com
Incident
- Discovered
- Aug 1, 2024
- Materiality determined
- —
- Notification sent
- Mar 28, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement of the incidentContinuing to support federal law enforcement’s investigation into the incident
Compliance
- Time to disclose
- 34 weeks(239 days from discovery to filing)
- Compliance flags
- CA 60-day late · 239dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 1, 2024→ Notified: Mar 28, 2025239d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.