HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Smith & Wesson
bd_79e8293973f49c37 · schema v1 · pii pii-v1
Full breach record for Smith & Wesson →Smith & Company, a CPA firm, notified clients of a data breach involving its third-party software provider, Intuit. On March 23, 2021, Intuit reported that the firm's Electronic Filing ID for IRS tax filings was compromised. The incident potentially exposed client PII, including names, addresses, SSNs, and bank account numbers. Smith & Company ceased transmission of impacted returns, engaged Intuit's Fraud Department, and implemented security upgrades. Notifications were sent to clients in multiple states, including New Hampshire, Rhode Island, and others.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/smith-certified-public-accountants-20210506.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 6, 2021
- Raw hash
- 9e8a8a237654ec07c730699b96566c20699ff659aa770e32c3b8049c6373b0e7
Reporting entity
- Name
- Smith & Wessonnorm: smith wesson
- Domain
- smith-wesson.com
Victim entity
- Name
- Smith & Wessonnorm: smith wesson
- Domain
- smith-wesson.com
Incident
- Discovered
- Mar 23, 2021
- Materiality determined
- —
- Notification sent
- Apr 3, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.