DisclosureLens
HackingFinancial ServicesProfessional ServicesFinanceStolen CredentialsTargetedData ExfiltratedGovernment IDIdentity (basic)HighContained

Woodruff Sawyer & Co.

bd_751f17dbb3c4b49c · schema v1 · pii pii-v1

Severity

High

Discovered

Feb 5, 2024

Filed

Mar 4, 2024

To disclose

28 days

Affected · nationwide

3,08725 in this filing

Linked

7 filings

Confidence

64%
Full breach record for Woodruff Sawyer & Co.6 incidents on file

Woodruff-Sawyer & Co., an insurance brokerage and risk consulting firm based in San Francisco, reported a cybersecurity incident to the Maine Attorney General. On January 20, 2024, an executive was targeted by a SIM-swapping attack, allowing an unauthorized actor to reset work passwords and access cloud systems. The actor downloaded a subset of files containing client data, specifically names and driver's license numbers. The breach affected 3,087 individuals, including 25 Maine residents. Notification was sent on March 4, 2024, offering 24 months of credit monitoring and identity restoration services.

Maine clockDiscovered Feb 5, 2024Filed with AG Mar 4, 202428d ME AG ≤30d28 days discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 16 days
discovery → filing · 28 days

Jan 20, 2024

Begins

Feb 5, 2024

Discovered

Mar 4, 2024

Filed

vs. sector median

4 wks faster

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filingsup to 116d gap

Filing propagation · 7 filings · 6 states

View merged incident ↗
Montana State AGMar 4 · first
Indiana State AGMar 4 · first
Maine State AGMar 4 · first · this page

Pattern: first filing Mar 4 (MT), last Jun 28 (CA) — a 116-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.