HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
GRAYROBINSON, P.A.
bd_97efcfd5f4cb89ba · schema v1 · pii pii-v1
Full breach record for GRAYROBINSON, P.A. →GrayRobinson, P.A. detected unauthorized access to its network on March 24, 2025. The incident involved potential exposure of personal information, including full names and Social Security numbers, for individuals whose data may have been accessed between March 5, 2025, and March 24, 2025. The firm secured its network, reported the incident to law enforcement, and engaged external cybersecurity professionals. Affected individuals are being offered complimentary credit monitoring services.
California clockDiscovered Mar 24, 2025 → Notified Apr 13, 2026385d ✗ CA 60-day late13 months discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_35cc442280a9189cMontana State AGfiled 2026-04-24Candidate
- bd_70a89970a20e2cd6HHS OCRfiled 2026-04-24Verified
- bd_d2707ef1537a6e5bIndiana State AGfiled 2026-04-24Verified
- bd_5befb58f749743e9New Hampshire State AGfiled 2026-04-29(5d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 13d gap
- bd_aa3a4069dcb4c338California State AGfiled 2026-05-04(10d gap)Verified
- bd_cca7851fcf929bc5Vermont State AGfiled 2026-05-05(11d gap)Verified
- bd_794b695cf033f8abNew Hampshire State AGfiled 2026-05-07(13d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-622314
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 24, 2026
- Raw hash
- 317959c82f28290cb87bf2d2f64f18a685a936880032a5888f304f9e91e0b802
Reporting entity
- Name
- GRAYROBINSON, P.A.norm: grayrobinson
Victim entity
- Name
- GRAYROBINSON, P.A.norm: grayrobinson
Incident
- Discovered
- Mar 24, 2025
- Materiality determined
- —
- Notification sent
- Apr 13, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement
Compliance
- Time to disclose
- 13 months(396 days from discovery to filing)
- Compliance flags
- CA 60-day late · 385dCA AG copy ≤15d · 11d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 24, 2025→ Notified: Apr 13, 2026385d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Apr 13, 2026→ AG copy submitted: Apr 24, 202611d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.