DisclosureLens
HackingProfessional ServicesProfessional ServicesStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDFinancial accountEmploymentMediumContained

Ondracek & Company

bd_b6c0e18367108f59 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 6, 2017

Filed

Mar 13, 2017

To disclose

5 weeks

Affected

Not disclosed

Linked

3 filings

Confidence

64%
Full breach record for Ondracek & Company

Ondracek & Company experienced unauthorized access to its systems via Remote Desktop Protocol between November 21, 2016, and February 6, 2017. The company discovered the incident on February 6, 2017, when clients reported IRS notifications regarding fraudulent tax returns. Affected data included names, SSNs, DOBs, addresses, employment info, and bank account details. The company engaged forensic investigators, notified law enforcement and regulators, and offered credit monitoring.

California clockDiscovered Feb 6, 2017Notified Mar 15, 201737d CA 60-day OK5 weeks discovery → filing

Incident timeline

undetected · 77 days
discovery → filing · 5 weeks / 35 days

Nov 21, 2016

Begins

Feb 6, 2017

Discovered

Mar 13, 2017

Filed

vs. sector median

14 wks faster

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Montana State AGMar 13 · first
California State AGMar 13 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.