HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Grellas Shah LLP
bd_50f122b56b1dddef · schema v1 · pii pii-v1
Full breach record for Grellas Shah LLP →Grellas Shah LLP, a law firm, disclosed a cybersecurity incident involving unauthorized access to employee email accounts between December 20, 2021, and March 28, 2022. The breach exposed personal information including names, Social Security numbers, driver's license numbers, passport numbers, financial account numbers, payment card numbers, and medical information. The firm engaged a cybersecurity firm, secured the accounts, and offered one year of Equifax Credit Watch Gold to affected individuals.
California clockDiscovered Jul 15, 2022 → Notified Jul 15, 20220d ✓ CA 60-day OK7 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3ca83b0554b466cbNew Hampshire State AGfiled 2022-09-01Verified
- bd_57d0ecb4ab223733Maine State AGfiled 2022-09-01Verified
- bd_a1a6335d399500abMontana State AGfiled 2022-09-01Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-556836
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 1, 2022
- Raw hash
- f0a4ade62a3b2f254453808dcfed99ed6a04c16396a59d5104043601708c7f1c
Reporting entity
- Name
- Grellas Shah LLPnorm: grellas shah
Victim entity
- Name
- Grellas Shah LLPnorm: grellas shah
Incident
- Discovered
- Jul 15, 2022
- Materiality determined
- —
- Notification sent
- Jul 15, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 15, 2022→ Notified: Jul 15, 20220d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.