DisclosureLens
HackingProfessional ServicesProfessional ServicesCustomer Data InvolvedPIIIdentity (basic)LowContained

SAX

bd_a57bf44b11d3263a · schema v1 · pii pii-v1

Severity

Low

Discovered

Aug 7, 2024

Filed

Dec 22, 2025

To disclose

17 months

Affected

Not disclosed

Linked

11 filings

Confidence

65%
Full breach record for SAX

Sax LLP notified the California Attorney General of a security incident where personal information may have been viewed or acquired without authorization. The firm detected suspicious activity on August 7, 2024, and engaged cybersecurity experts. The investigation concluded that some personal information, including names and potentially other data, was involved. Notification letters were sent on December 1, 2025. Sax LLP implemented additional security measures and offered complimentary identity protection services through Epiq.

California clockDiscovered Aug 7, 2024Notified Dec 1, 2025481d CA 60-day late17 months discovery → filing

Incident timeline

discovery → filing · 17 months / 502 days

Aug 7, 2024

Discovered

Dec 22, 2025

Filed

vs. sector median

+54 wks slower

This filing is one of 11 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (10) · sorted by filing gap

Show 6 more filingsup to 7d gap

Filing propagation · 11 filings · 11 states

View merged incident ↗

Pattern: first filing Dec 16 (NE), last Dec 29 (TX) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.