Clifton Larson Allen
bd_aa2a408399adf1c8 · schema v1 · pii pii-v1
Full breach record for Clifton Larson Allen →CliftonLarsonAllen LLP (CLA) disclosed that on August 28, 2017, a third-party service provider's client portal was compromised via stolen user credentials. Unauthorized access resulted in the exposure of client PII, including names, addresses, DOBs, SSNs, and bank account numbers. CLA notified the IRS/CI, secured accounts, and offered 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 28, 2017
Discovered
Sep 20, 2017
Filed
vs. sector median
14 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.