HackingFinancial ServicesProfessional ServicesFinanceStolen CredentialsCapture App DataCustomer Data InvolvedData ExfiltratedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Shelton & Company, CPAs, P.C.
bd_b2b731d9f453b787 · schema v1 · pii pii-v1
Full breach record for Shelton & Company, CPAs, P.C. →On August 15, 2024, Shelton & Company, CPAs, P.C., a Virginia-based accounting firm, detected suspicious activity in its email environment. Investigation completed November 4, 2024 confirmed that the contents of one employee mailbox may have been acquired without authorization, potentially exposing client PII including names, addresses, dates of birth, and Social Security numbers. Two Maine residents were among 2,166 total affected individuals. Notifications were sent December 9, 2024.
Maine clockDiscovered Nov 4, 2024 → Filed with AG Dec 10, 202436d ⏱ ME AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_c50d0393d3bfc295Montana State AGfiled 2024-12-09(1d gap)Candidate
- bd_caac138267f80b58Vermont State AGfiled 2024-12-09(1d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/50bc25f6-e2a1-4ac8-8e00-0f613abc6c24.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 10, 2024
- Raw hash
- 27920ef0a8c5b9fd052bce738f13802aecded15186ab22229ff1117b1a8407b6
Reporting entity
- Name
- Shelton & Company, CPAs, P.C.norm: shelton company cpas
- Industry
- Financial Services
Victim entity
- Name
- Shelton & Company, CPAs, P.C.norm: shelton company cpas
- Industry
- Financial Services
- Industry
- Financial ServicesllmProfessional Servicesllm
Incident
- Discovered
- Nov 4, 2024
- Materiality determined
- —
- Notification sent
- Dec 9, 2024
- Affected individuals
- 2
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Maine Attorney General – Security Breach Notification
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- ME AG >30d · 36d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Nov 4, 2024→ Filed with AG: Dec 10, 202436d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.