HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
TaxSlayer
bd_9f2d4f3a097040a1 · schema v1 · pii pii-v1
Full breach record for TaxSlayer →TaxSlayer disclosed a data breach affecting California residents. An unauthorized third party accessed accounts between October 10, 2015, and December 21, 2015, using credentials stolen from another online service. Affected data included names, addresses, and Social Security numbers. TaxSlayer disabled access, required password resets, and offered 12 months of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_40ae479f097ab3a4Montana State AGfiled 2016-01-29Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-59859
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 29, 2016
- Raw hash
- edf0e0aec43299e4e54cb8fe8f315c08c3bbfef96dd857432900268c03f2bb8e
Reporting entity
- Name
- TaxSlayernorm: taxslayer
Victim entity
- Name
- TaxSlayernorm: taxslayer
Incident
- Discovered
- Jan 13, 2016
- Materiality determined
- Jan 27, 2016
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.