Woodruff Sawyer & Co.
bd_751f17dbb3c4b49c · schema v1 · pii pii-v1
Full breach record for Woodruff Sawyer & Co. →6 incidents on fileWoodruff-Sawyer & Co., an insurance brokerage and risk consulting firm based in San Francisco, reported a cybersecurity incident to the Maine Attorney General. On January 20, 2024, an executive was targeted by a SIM-swapping attack, allowing an unauthorized actor to reset work passwords and access cloud systems. The actor downloaded a subset of files containing client data, specifically names and driver's license numbers. The breach affected 3,087 individuals, including 25 Maine residents. Notification was sent on March 4, 2024, offering 24 months of credit monitoring and identity restoration services.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 20, 2024
Begins
Feb 5, 2024
Discovered
Mar 4, 2024
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Montana State AGbd_cc972661d63c3fee2024-03-04Verified
- Indiana State AGbd_d17b63c8574e82872024-03-04Verified
- Massachusetts State AGbd_b31da2b464533ad72024-03-05 · +1dVerified
- New Hampshire State AGbd_c827d916f6654c942024-03-18 · +14dVerified
Show 2 more filings ↓Show fewer ↑up to 116d gap
- California State AGbd_cdf69a212ead0ef12024-03-20 · +16dVerified
- California State AGbd_0a098efd7c6a3bea2024-06-28 · +116dVerified
Filing propagation · 7 filings · 6 states
View merged incident ↗Pattern: first filing Mar 4 (MT), last Jun 28 (CA) — a 116-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.