HackingPhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMINORMediumContained
Mohr CPAs LLP
bd_ae703b097bffb835 · schema v1 · pii pii-v1
Full breach record for Mohr CPAs LLP →Mohr CPAs LLP notified New Hampshire residents of a security incident discovered on September 29, 2023, involving unauthorized access to a server via compromised email credentials. Files were exfiltrated, potentially impacting client PII, SSNs, and tax data. Four NH residents were notified on November 22, 2023. The firm engaged forensic specialists, notified the IRS and other regulators, and offered credit monitoring services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_7bcbe0140149a87fVermont State AGfiled 2023-11-22Verified
- bd_ab1197eef0c79b57Montana State AGfiled 2023-11-22Candidate
- bd_cc5351b2ecbf5fa1Maine State AGfiled 2023-11-22Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mohr-cpas-20231122.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2023
- Raw hash
- 2c5205e9d3a2aaeb2e16a19e404c41c73abd77e7449c3016709c71b625da8c5f
Reporting entity
- Name
- Mohr Partnersnorm: mohr partners
- Domain
- mohrpartners.com
Victim entity
- Name
- Mohr CPAs LLPnorm: mohr cpas
Incident
- Discovered
- Sep 29, 2023
- Materiality determined
- Oct 23, 2023
- Notification sent
- Nov 22, 2023
- Affected individuals
- 4
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTMINOR
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Internal Revenue Service (“IRS”)Notified Federation of Tax Administrators (“FTA”)Notified Wisconsin Department of RevenueCooperated with these agencies’ investigations
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.