MalwareRansomwareData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENTMediumContained
Stallcup & Associates, CPAs
bd_c4d60de0c8245cfd · schema v1 · pii pii-v1
Full breach record for Stallcup & Associates, CPAs →Stallcup & Associates, CPAs experienced a ransomware incident on July 11, 2016, where network files were encrypted. The firm detected the virus within an hour and contained it. No evidence of data exfiltration was found, but client tax information (including SSNs, bank account details, and W-2s) was on the affected drives. The firm engaged forensic investigators, notified the FBI and credit agencies, and offered 12 months of identity protection to affected individuals.
California clockDiscovered Jul 11, 2016 → Notified Sep 21, 201672d ✗ CA 60-day late10 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_86a919b8e15d195aMontana State AGfiled 2016-09-21Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-63986
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 21, 2016
- Raw hash
- d34fe8fa2cecc581942ab85af3927458f9d1a98469890ffb0b0bdaea59d90bd3
Reporting entity
- Name
- Stallcup & Associates, CPAsnorm: stallcup associates cpas
Victim entity
- Name
- Stallcup & Associates, CPAsnorm: stallcup associates cpas
Incident
- Discovered
- Jul 11, 2016
- Materiality determined
- —
- Notification sent
- Sep 21, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with the FBIFiled notice with all three consumer reporting agenciesNotifying offices of applicable State Attorney Generals
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- CA 60-day late · 72d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 11, 2016→ Notified: Sep 21, 201672d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.