Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Chiorini, Hunt & Jacobs
bd_7aeb3f4f1cd9a774 · schema v1 · pii pii-v1
Full breach record for Chiorini, Hunt & Jacobs →Chiorini, Hunt & Jacobs, a professional services firm, disclosed a data breach affecting client information. Between July 1 and September 27, 2017, attackers used phishing emails to compromise specific email accounts ([REDACTED-EMAIL], [REDACTED-EMAIL], [REDACTED-EMAIL]). The breach exposed client tax returns, SSNs, birthdates, addresses, and bank account details. The firm notified the FBI, credit bureaus, and state agencies, and provided one year of credit monitoring via TransUnion. No internal network was accessed.
California clockDiscovered Sep 27, 2017 → Notified Oct 27, 201730d ✓ CA 60-day OK4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-103063
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 27, 2017
- Raw hash
- 9be3d307f0eb2b1ed662ea63b72723f1cd08b00893d7686f019e344550a68257
Reporting entity
- Name
- Chiorini, Hunt & Jacobsnorm: chiorini hunt jacobs
- Domain
- chj.com
Victim entity
- Name
- Chiorini, Hunt & Jacobsnorm: chiorini hunt jacobs
- Domain
- chj.com
Incident
- Discovered
- Sep 27, 2017
- Materiality determined
- —
- Notification sent
- Oct 27, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of InvestigationNotified applicable state agencies
- Initial access
- phishing_link
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 27, 2017→ Notified: Oct 27, 201730d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.