HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Mohr CPAs LLP
bd_7bcbe0140149a87f · schema v1 · pii pii-v1
Full breach record for Mohr CPAs LLP →Mohr CPAs LLP notified consumers of a security incident discovered on September 29, 2023, involving unauthorized access to a server via compromised email credentials. Files containing names, SSNs, DOBs, and driver's license numbers were exfiltrated. Mohr CPAs engaged forensic specialists, secured the environment, and cooperated with the IRS and other agencies. Credit monitoring and fraud assistance are offered to affected individuals.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_ab1197eef0c79b57Montana State AGfiled 2023-11-22Candidate
- bd_ae703b097bffb835New Hampshire State AGfiled 2023-11-22Verified
- bd_cc5351b2ecbf5fa1Maine State AGfiled 2023-11-22Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-11-22-mohr-cpas-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2023
- Raw hash
- d5fd63b27fc4e8024a1be9dd47979004928025a7f906a4bc2f12ed6fe4333dd8
Reporting entity
- Name
- Mohr CPAs LLPnorm: mohr cpas
Victim entity
- Name
- Mohr CPAs LLPnorm: mohr cpas
Incident
- Discovered
- Sep 29, 2023
- Materiality determined
- Nov 22, 2023
- Notification sent
- Nov 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- in communication with the Internal Revenue Servicein communication with the Wisconsin Department of Revenuein communication with the Federation of Tax Associatescooperated with these agencies’ investigations
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.