HackingData ExfiltratedData PublishedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPIIMediumContained
Kronick Moskovitz Tiedemann & Girard
bd_78a8971981b2e05c · schema v1 · pii pii-v1
Full breach record for Kronick Moskovitz Tiedemann & Girard →Kronick, Moskovitz, Tiedemann & Girard, a California law firm, disclosed a cybersecurity incident in August 2024 involving unauthorized access by an unknown third party. The attacker accessed internal systems and exfiltrated personal information including names, SSNs, DOBs, driver's license numbers, and medical/health insurance data. The firm engaged forensic experts, reset credentials, and notified law enforcement. The attacker briefly posted data on a dark web site before it was removed. Kronick offered 24 months of Experian credit monitoring to affected individuals.
Vermont clock✗ VT AG >45 bday34 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
A leak claim by rhysida about this victim predates this filing by 234 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_485be91e1544288fLeak Siterhysidafiled 2024-08-22(217d gap)Verified
- bd_5115b8f34c464313Leak Siterhysidafiled 2024-08-06(234d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_3b9c18091611fea2California State AGfiled 2025-03-28Verified by operator
- bd_85953c04009ba220Indiana State AGfiled 2025-03-28Verified
- bd_d2db47f3b9d4421fHHS OCRfiled 2025-02-28(28d gap)Verified
- bd_f96d420733a272ebCalifornia State AGfiled 2025-02-28(28d gap)Verified by operator
Show 1 more filing ↓Show fewer ↑up to 63d gap
- bd_26e21b83d173f48cCalifornia State AGfiled 2025-05-30(63d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-03-28-kronick-moskovitz-tiedemann-girard-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 28, 2025
- Raw hash
- ce473acb921c7ce971656f43f4e568618dfa1627223ed5e97196014e5a748d32
Reporting entity
- Name
- Kronick Moskovitz Tiedemann & Girardnorm: kronick moskovitz tiedemann girard
- Domain
- kmtg.com
Victim entity
- Name
- Kronick Moskovitz Tiedemann & Girardnorm: kronick moskovitz tiedemann girard
- Domain
- kmtg.com
Incident
- Discovered
- Aug 1, 2024
- Materiality determined
- —
- Notification sent
- Mar 28, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 34 weeks(239 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.