Ondracek & Company
bd_b6c0e18367108f59 · schema v1 · pii pii-v1
Full breach record for Ondracek & Company →Ondracek & Company experienced unauthorized access to its systems via Remote Desktop Protocol between November 21, 2016, and February 6, 2017. The company discovered the incident on February 6, 2017, when clients reported IRS notifications regarding fraudulent tax returns. Affected data included names, SSNs, DOBs, addresses, employment info, and bank account details. The company engaged forensic investigators, notified law enforcement and regulators, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 21, 2016
Begins
Feb 6, 2017
Discovered
Mar 13, 2017
Filed
vs. sector median
14 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Montana State AGbd_f0e6b9344aca60322017-03-13Candidate
- Massachusetts State AGbd_f19d5829f65386da2017-03-14 · +1dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.