HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
GRAYROBINSON, P.A.
bd_aa3a4069dcb4c338 · schema v1 · pii pii-v1
Full breach record for GRAYROBINSON, P.A. →GrayRobinson, P.A. detected unauthorized access to its network on March 24, 2025. Investigation determined files may have been accessed or removed between March 5 and March 24, 2025. Affected data includes full name and Social Security numbers. The firm secured the network, reported to law enforcement, engaged external cybersecurity professionals, and offered complimentary identity monitoring services.
California clockDiscovered Mar 24, 2025 → Notified Apr 13, 2026385d ✗ CA 60-day late14 months discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_cca7851fcf929bc5Vermont State AGfiled 2026-05-05(1d gap)Verified
- bd_794b695cf033f8abNew Hampshire State AGfiled 2026-05-07(3d gap)Verified
- bd_5befb58f749743e9New Hampshire State AGfiled 2026-04-29(5d gap)Verified
- bd_35cc442280a9189cMontana State AGfiled 2026-04-24(10d gap)Candidate
Show 3 more filings ↓Show fewer ↑up to 10d gap
- bd_70a89970a20e2cd6HHS OCRfiled 2026-04-24(10d gap)Verified
- bd_97efcfd5f4cb89baCalifornia State AGfiled 2026-04-24(10d gap)Verified
- bd_d2707ef1537a6e5bIndiana State AGfiled 2026-04-24(10d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-622783
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 4, 2026
- Raw hash
- de1fd09d06db4752b784d7eb24ee602fd32c054c058019c2130f192d8af3480f
Reporting entity
- Name
- GRAYROBINSON, P.A.norm: grayrobinson
Victim entity
- Name
- GRAYROBINSON, P.A.norm: grayrobinson
Incident
- Discovered
- Mar 24, 2025
- Materiality determined
- —
- Notification sent
- Apr 13, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 14 months(406 days from discovery to filing)
- Compliance flags
- CA 60-day late · 385dCA AG copy >15d · 21d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 24, 2025→ Notified: Apr 13, 2026385d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Apr 13, 2026→ AG copy submitted: May 4, 202621d 15 calendar days CA AG copy >15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.