HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIHighContained
Miller Kaplan Arase, LLP
bd_a295f1709ecb68e7 · schema v1 · pii pii-v1
Full breach record for Miller Kaplan Arase, LLP →Miller Kaplan Arase LLP experienced unauthorized access to an employee's email account on March 22, 2019. The incident potentially exposed personal information including names, addresses, SSNs, dates of birth, financial account numbers, and health information for approximately 7,442 California residents. The firm engaged forensic investigators, notified law enforcement, and implemented MFA and password resets. Affected individuals were offered 36 months of credit monitoring.
California clockDiscovered Mar 22, 2019 → Notified Jul 10, 2019110d ✗ CA 60-day late25 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7,442 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-150465
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2019
- Raw hash
- 5c13a42669328f902b4d36b07e31f1d86ab4c899a2a3533ef0e64c4342288f1b
Reporting entity
- Name
- Miller Kaplan Arase, LLPnorm: miller kaplan arase
Victim entity
- Name
- Miller Kaplan Arase, LLPnorm: miller kaplan arase
Incident
- Discovered
- Mar 22, 2019
- Materiality determined
- —
- Notification sent
- Jul 10, 2019
- Affected individuals
- 7,442
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified California Attorney General on July 10, 2019Reported to the FBIReported to local law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 25 weeks(173 days from discovery to filing)
- Compliance flags
- CA 60-day late · 110d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 22, 2019→ Notified: Jul 10, 2019110d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.