HackingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
SAX
bd_556c3ae504f7e82c · schema v1 · pii pii-v1
Full breach record for SAX →Sax LLP, a professional services firm, notified Delaware AG of a security incident discovered on August 7, 2024. Suspicious activity led to an investigation revealing unauthorized access to personal information, including names and other PII. No evidence of misuse was found. Sax engaged cybersecurity experts, FBI, and provided credit monitoring via Epiq. Notification to affected individuals was completed by December 1, 2025.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_a0269a5e4239280fIndiana State AGfiled 2025-12-16Verified
- bd_03368ea6c198e1b3Montana State AGfiled 2025-12-22(6d gap)Verified
- bd_6b0331732b1d6680Maine State AGfiled 2025-12-22(6d gap)Verified
- bd_70f3b36fdd6d270fNew Hampshire State AGfiled 2025-12-22(6d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 13d gap
- bd_a57bf44b11d3263aCalifornia State AGfiled 2025-12-22(6d gap)Candidate
- bd_ce441aca74d4f237Vermont State AGfiled 2025-12-22(6d gap)Verified
- bd_db6dcf921571714aSouth Carolina State AGfiled 2025-12-23(7d gap)Verified
- bd_1ef0f101196477a7Texas State AGfiled 2025-12-29(13d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2026/01/Sax_-Reg-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 16, 2025
- Raw hash
- 212cec62cfe261a4988632dbf3556b33e0082b03ab11123095edbbc7f88a481b
Reporting entity
- Name
- SAXnorm: sax
- Domain
- saxadvisorygroup.com
Victim entity
- Name
- SAXnorm: sax
- Domain
- saxadvisorygroup.com
Incident
- Discovered
- Aug 7, 2024
- Materiality determined
- —
- Notification sent
- Dec 1, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 months(496 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.