HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
The Smith and Oby Company
bd_6c8198fee11d6d5a · schema v1 · pii pii-v1
Full breach record for The Smith and Oby Company →Smith and Company, a CPA firm, notified clients that their Electronic Filing ID with the IRS was compromised via their third-party software provider, Intuit, on March 23, 2021. The incident potentially exposed client tax data including names, addresses, dates of birth, SSNs, and bank account numbers. Smith and Company ceased transmissions, obtained a new EFIN, and engaged cybersecurity experts. No specific count of affected individuals was disclosed in the notice.
California clockDiscovered Mar 23, 2021 → Notified Apr 22, 202130d ✓ CA 60-day OK4 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-540240
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 22, 2021
- Raw hash
- 3157ad80b5d57948b0baf309fa998825b536d7f7227a6d0c434e3146da37767b
Reporting entity
- Name
- The Smith and Oby Companynorm: the smith and oby
Victim entity
- Name
- The Smith and Oby Companynorm: the smith and oby
Incident
- Discovered
- Mar 23, 2021
- Materiality determined
- —
- Notification sent
- Apr 22, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the IRS
- Third party
- via Intuit
- Initial access
- supply_chain
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 23, 2021→ Notified: Apr 22, 202130d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.