HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
Smith & James, CPAs
bd_aabbe387857e7d4e · schema v1 · pii pii-v1
Full breach record for Smith & James, CPAs →Smith & James, CPAs experienced unauthorized access to its email environment on March 5, 2026, discovered on March 9, 2026. An unknown actor accessed and acquired personal information including names, Social Security numbers, dates of birth, medical information, and health insurance information. The firm engaged cybersecurity experts, secured its network, and notified the IRS. Affected individuals are offered 12 months of complimentary credit monitoring and identity theft protection.
California clockDiscovered Mar 9, 2026 → Notified May 28, 202680d ✗ CA 30-day late11 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-624055
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 28, 2026
- Raw hash
- 7337086e8b45423e4817de95ecf8005bceb462daddee797f9332c1e9a2867a37
Reporting entity
- Name
- Smith & James, CPAsnorm: smith james cpas
Victim entity
- Name
- Smith & James, CPAsnorm: smith james cpas
Incident
- Discovered
- Mar 9, 2026
- Materiality determined
- —
- Notification sent
- May 28, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Reported this incident to the Internal Revenue Service
Compliance
- Time to disclose
- 11 weeks(80 days from discovery to filing)
- Compliance flags
- CA 30-day late · 80dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 9, 2026→ Notified: May 28, 202680d 30 calendar days CA 30-day late California Consumers notified: May 28, 2026→ AG copy submitted: May 28, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.