HackingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
SAX
bd_a57bf44b11d3263a · schema v1 · pii pii-v1
Full breach record for SAX →Sax LLP notified the California Attorney General of a security incident where personal information may have been viewed or acquired without authorization. The firm detected suspicious activity on August 7, 2024, and engaged cybersecurity experts. The investigation concluded that some personal information, including names and potentially other data, was involved. Notification letters were sent on December 1, 2025. Sax LLP implemented additional security measures and offered complimentary identity protection services through Epiq.
California clockDiscovered Aug 7, 2024 → Notified Dec 1, 2025481d ✗ CA 60-day late17 months discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_03368ea6c198e1b3Montana State AGfiled 2025-12-22Verified
- bd_6b0331732b1d6680Maine State AGfiled 2025-12-22Verified
- bd_70f3b36fdd6d270fNew Hampshire State AGfiled 2025-12-22Verified
- bd_ce441aca74d4f237Vermont State AGfiled 2025-12-22Verified
Show 4 more filings ↓Show fewer ↑up to 7d gap
- bd_db6dcf921571714aSouth Carolina State AGfiled 2025-12-23(1d gap)Verified
- bd_556c3ae504f7e82cDelaware State AGfiled 2025-12-16(6d gap)Verified
- bd_a0269a5e4239280fIndiana State AGfiled 2025-12-16(6d gap)Verified
- bd_1ef0f101196477a7Texas State AGfiled 2025-12-29(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-616199
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2025
- Raw hash
- 438b1bef7a671610f1e45e38520686935e8c1b53aa9544dd2d2f8853d155be3c
Reporting entity
- Name
- SAXnorm: sax
- Domain
- saxadvisorygroup.com
Victim entity
- Name
- SAXnorm: sax
- Domain
- saxadvisorygroup.com
Incident
- Discovered
- Aug 7, 2024
- Materiality determined
- —
- Notification sent
- Dec 1, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unknown
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation of the incident
Compliance
- Time to disclose
- 17 months(502 days from discovery to filing)
- Compliance flags
- CA 60-day late · 481d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 7, 2024→ Notified: Dec 1, 2025481d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.