DisclosureLens
HackingProfessional ServicesProfessional ServicesStolen CredentialsCustomer Data InvolvedData ExfiltratedIdentity (basic)Government IDFinancial accountPIIMediumContained

Clifton Larson Allen

bd_aa2a408399adf1c8 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 28, 2017

Filed

Sep 20, 2017

To disclose

23 days

Affected

2state residents only

Confidence

66%
Full breach record for Clifton Larson Allen

CliftonLarsonAllen LLP (CLA) disclosed that on August 28, 2017, a third-party service provider's client portal was compromised via stolen user credentials. Unauthorized access resulted in the exposure of client PII, including names, addresses, DOBs, SSNs, and bank account numbers. CLA notified the IRS/CI, secured accounts, and offered 12 months of credit monitoring.

Incident timeline

discovery → filing · 23 days

Aug 28, 2017

Discovered

Sep 20, 2017

Filed

vs. sector median

14 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.