DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryGovernment IDIdentity (basic)MediumContained

Eichenbaum, Comer & Ratynets

bd_b118da49233dc3aa · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 20, 2022

Filed

Feb 17, 2022

To disclose

28 days

Affected

Not disclosed

Linked

2 filings

Confidence

63%
Full breach record for Eichenbaum, Comer & Ratynets2 incidents on file

Eichenbaum Comer & Ratynets AAC disclosed a phishing incident where an unauthorized party accessed an employee email account between October 4 and October 8, 2020. The firm discovered the breach on January 20, 2022, after forensic investigation revealed the accessed account contained personal information, including Social Security numbers. The firm secured the account, engaged external cybersecurity professionals, and is offering one year of complimentary credit monitoring to affected individuals.

Incident timeline

undetected · 473 days
discovery → filing · 28 days

Oct 4, 2020

Begins

Jan 20, 2022

Discovered

Feb 17, 2022

Filed

vs. sector median

15 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Indiana State AGFeb 17 · first
California State AGFeb 17 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.