HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Woodruff Sawyer & Co.
bd_cdf69a212ead0ef1 · schema v1 · pii pii-v1
Full breach record for Woodruff Sawyer & Co. →Woodruff-Sawyer & Co. experienced a data breach on January 20, 2024, when an unauthorized third party gained access to computer systems via SIM swapping of an executive's phone number. The attacker reset the executive's password and downloaded a small subset of files containing personal information. The company engaged forensic experts, notified the FBI, and amended security controls to prevent SIM swapping. Affected individuals are offered 24 months of Experian IdentityWorks.
California clockDiscovered Jan 20, 2024 → Notified Mar 20, 202460d ✓ CA 60-day OK9 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_c827d916f6654c94New Hampshire State AGfiled 2024-03-18(2d gap)Verified
- bd_751f17dbb3c4b49cMaine State AGfiled 2024-03-04(16d gap)Candidate
- bd_cc972661d63c3feeMontana State AGfiled 2024-03-04(16d gap)Verified
- bd_d17b63c8574e8287Indiana State AGfiled 2024-03-04(16d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582759
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 20, 2024
- Raw hash
- a79d9c6ea35f89baf065154ada3184fb1f2979ae2e92d684ffc9b5b8623b11b4
Reporting entity
- Name
- Woodruff Sawyer & Co.norm: woodruff sawyer
- Domain
- woodruffsawyer.com
Victim entity
- Name
- Woodruff Sawyer & Co.norm: woodruff sawyer
- Domain
- woodruffsawyer.com
Incident
- Discovered
- Jan 20, 2024
- Materiality determined
- —
- Notification sent
- Mar 20, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation (FBI)
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 60d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 20, 2024→ Notified: Mar 20, 202460d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.