DisclosureLens
HackingProfessional ServicesProfessional ServicesStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIdentity (basic)Government IDFinancial accountHealth (basic)MediumContained

Calibre CPA Group

bd_469bb67cd6efc5df · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Sep 9, 2019

To disclose

Affected

553state residents only

Linked

6 filings

Confidence

66%
Full breach record for Calibre CPA Group2 incidents on file

Calibre CPA Group experienced unauthorized access to employee email accounts and a server between March 11, 2019, and May 7, 2019. The incident affected 553 California residents, exposing personal information including names, Social Security numbers, financial account details, driver's license numbers, and medical information. Calibre engaged forensic experts, reset passwords, implemented dual-factor authentication, and provided two years of identity monitoring services through Kroll. The investigation is ongoing, but the incident is considered contained.

Incident timeline

Mar 11, 2019

Begins

Sep 9, 2019

Filed

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 31d gap

Filing propagation · 6 filings · 6 states

View merged incident ↗
Massachusetts State AGAug 26 · first
Montana State AGAug 26 · first
California State AG+14d · this page

Pattern: first filing Aug 26 (MA), last Oct 10 (WA) — a 45-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.