HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedRansom DemandedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTPIIMediumContained
Wheeler & Egger, CPAs
bd_8e1c0502d77c4151 · schema v1 · pii pii-v1
Full breach record for Wheeler & Egger, CPAs →Wheeler & Egger, CPAs, LLP submitted a supplemental breach notification to the California AG regarding unauthorized e-filing of tax returns using stolen client credentials between August 3-9, 2016. The incident affected 45 individuals, exposing SSNs, financial account data, and PII. The firm removed malware, engaged law enforcement (FBI, IRS, Secret Service), and provided one year of credit monitoring.
California clockDiscovered Aug 15, 2016 → Notified Sep 13, 201629d ✓ CA 60-day OK27 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_7ed17255263123b8South Carolina State AGfiled 2016-09-12(1d gap)Candidate
- bd_1a0b44c384a5de16Montana State AGfiled 2016-09-13(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-63840
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2016
- Raw hash
- d2022670206b8e0a12082093a84c56c3150db70d5790f8d521877aa4726875db
Reporting entity
- Name
- Wheeler & Egger, CPAsnorm: wheeler egger cpas
Victim entity
- Name
- Wheeler & Egger, CPAsnorm: wheeler egger cpas
Incident
- Discovered
- Aug 15, 2016
- Materiality determined
- —
- Notification sent
- Sep 13, 2016
- Affected individuals
- 45
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the IRS, FTB, FBI, FDIC and the US Secret ServiceNotified the offices of the applicable State Attorney GeneralsNotified all three consumer reporting agencies
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 29d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 15, 2016→ Notified: Sep 13, 201629d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.