HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Jeff Anderson & Associates PA
bd_4d61d64c2f99c415 · schema v1 · pii pii-v1
Full breach record for Jeff Anderson & Associates PA →Jeff Anderson & Associates PA notified the California Attorney General of a data incident where an unauthorized party gained access to parts of their computer environment on September 18, 2025, and copied certain data. The incident involved a vulnerability in firewall protection technology affecting thousands of organizations. The firm engaged cybersecurity specialists, secured systems, notified law enforcement, and is offering 24 months of credit monitoring to affected individuals. No evidence of public disclosure or misuse was found.
California clockDiscovered Sep 18, 2025 → Notified Feb 10, 2026145d ✗ CA 60-day late21 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_116d30fdd32f2efdCalifornia State AGfiled 2026-02-26(16d gap)Verified
- bd_685ea336212807caVermont State AGfiled 2026-02-26(16d gap)Verified
- bd_17b24dde1fc4edb5Indiana State AGfiled 2025-12-19(53d gap)Candidate
- bd_91b364a07fe72e9cNew Hampshire State AGfiled 2025-12-19(53d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-618535
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 10, 2026
- Raw hash
- ef40a68ebca2fc125f2289cc0ccccedd2ad4f2b7512b7da80fb0df682c17fa1d
Reporting entity
- Name
- Jeff Anderson & Associates PAnorm: jeff anderson associates
- Domain
- andersonsadvocates.com
Victim entity
- Name
- Jeff Anderson & Associates PAnorm: jeff anderson associates
- Domain
- andersonsadvocates.com
Incident
- Discovered
- Sep 18, 2025
- Materiality determined
- —
- Notification sent
- Feb 10, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified California Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 weeks(145 days from discovery to filing)
- Compliance flags
- CA 60-day late · 145dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 18, 2025→ Notified: Feb 10, 2026145d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Feb 10, 2026→ AG copy submitted: Feb 10, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.