HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
Miller Kaplan Arase, LLP
bd_8a229e0f9ef9779a · schema v1 · pii pii-v1
Full breach record for Miller Kaplan Arase, LLP →Miller Kaplan Arase LLP reported that on March 22, 2019, an unauthorized individual gained access to an employee's email account. The incident potentially exposed names, addresses, Social Security numbers, dates of birth, plan information, financial account numbers, routing numbers, medical history, and health insurance information. The firm engaged forensic investigators, secured accounts, reset passwords, implemented MFA, and notified the FBI. Complimentary credit monitoring was offered to affected individuals.
California clockDiscovered Mar 22, 2019 → Notified Jul 10, 2019110d ✗ CA 60-day late16 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e476626cdbaaecf2Montana State AGfiled 2019-07-10Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-148817
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 10, 2019
- Raw hash
- 31ecbc7829ed8d9bd9579633b88c12b0ffe870cbfaa39c41614de62f960f2cb1
Reporting entity
- Name
- Miller Kaplan Arase, LLPnorm: miller kaplan arase
Victim entity
- Name
- Miller Kaplan Arase, LLPnorm: miller kaplan arase
Incident
- Discovered
- Mar 22, 2019
- Materiality determined
- —
- Notification sent
- Jul 10, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Reported this matter to the FBI and to local law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 weeks(110 days from discovery to filing)
- Compliance flags
- CA 60-day late · 110d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 22, 2019→ Notified: Jul 10, 2019110d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.