HackingStolen CredentialsDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumActive
Harder+Company Community Research
bd_93b68f8ca673fca9 · schema v1 · pii pii-v1
Full breach record for Harder+Company Community Research →Harder + Company Community Research, Inc. notified California AG of unauthorized access to business email accounts between April 17, 2021 and August 12, 2021. The incident involved the compromise of client personal information, including names, addresses, SSNs, driver's license numbers, and medical/insurance data. The company engaged forensic investigators, notified law enforcement, reset passwords, and offered identity theft protection services.
California clockDiscovered Aug 12, 2021 → Notified Jan 12, 2022153d ✗ CA 60-day late22 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_d5df4c771b5f3dc8Maine State AGfiled 2022-01-11Candidate
- bd_03a6a2c4216830c2Oregon State AGfiled 2022-01-12(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-549883
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 11, 2022
- Raw hash
- 5974cd45f3528bcfd49db52f7c6bc6a94e965f371eeb79d7d7f8c041ce3d08a0
Reporting entity
- Name
- Harder+Company Community Researchnorm: harder company community research
Victim entity
- Name
- Harder+Company Community Researchnorm: harder company community research
Incident
- Discovered
- Aug 12, 2021
- Materiality determined
- —
- Notification sent
- Jan 12, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 weeks(152 days from discovery to filing)
- Compliance flags
- CA 60-day late · 153d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 12, 2021→ Notified: Jan 12, 2022153d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.