Thomas Safran & Associates
bd_658fb97e998d4c95 · schema v1 · pii pii-v1
Full breach record for Thomas Safran & Associates →Thomas Safran & Associates notified the California Attorney General of a data security incident identified on September 8, 2025. An unauthorized party accessed a computer server containing confidential information, including names, dates of birth, addresses, and Social Security Numbers. The company engaged forensic experts, secured the environment, and is offering 12 months of credit monitoring to affected individuals in California, New Mexico, New York, North Carolina, Oregon, and Rhode Island.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 8, 2025
Begins
Sep 8, 2025
Discovered
Nov 24, 2025
Filed
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteplaybd_a296f580a5004dd12025-09-07 · +78dCandidate
Regulatory filings (1) · sorted by filing gap
- Massachusetts State AGbd_bc2d0341efd911f82025-12-23 · +29dVerified by operator
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Nov 24 (CA), last Dec 23 (MA) — a 29-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.