HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Waters & Kraus, LLP
bd_7d7e4c40b0995840 · schema v1 · pii pii-v1
Full breach record for Waters & Kraus, LLP →Waters & Kraus LLP, a law firm, reported a data breach involving unauthorized access to employee email accounts between December 5, 2019, and May 15, 2020. An unauthorized party accessed certain accounts, potentially viewing emails and attachments containing personal information of clients and business contacts. The firm engaged a cybersecurity firm, secured the environment, and offered one year of credit monitoring to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e27825421d308172Washington State AGfiled 2021-01-13Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-198514
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 13, 2021
- Raw hash
- 1caa8fa8daf0d410c3df7f90070060cc9b929d12a55a76a304d2267181b881ba
Reporting entity
- Name
- Waters & Kraus, LLPnorm: waters kraus
Victim entity
- Name
- Waters & Kraus, LLPnorm: waters kraus
Incident
- Discovered
- Dec 10, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email CollectionT1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.