MalwareRansomwareData ExfiltratedData EncryptedDelayed DiscoveryIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Bansley and Kiener, LLP
bd_d8742baa54ae80c0 · schema v1 · pii pii-v1
Full breach record for Bansley and Kiener, LLP →Bansley and Kiener, L.L.P. reported a security incident where systems were encrypted (ransomware) on Dec 10, 2020. While initially contained, exfiltration was confirmed on May 24, 2021. Affected data included full names and Social Security numbers of individuals in the Midwest region. The firm engaged forensic investigators, deployed SentinelOne EDR, reset passwords, and offered one year of Kroll identity monitoring services.
California clockDiscovered Dec 10, 2020 → Notified Aug 24, 2021257d ✗ CA 60-day late51 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_77b244465609bf86Montana State AGfiled 2021-11-30Verified
- bd_d4aad3f142f6fe81Maine State AGfiled 2021-11-30Verified
- bd_4bae8a61184e543cHHS OCRfiled 2021-12-03(3d gap)Verified
- bd_604e6a41f2e4e972HHS OCRfiled 2021-12-03(3d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-548063
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 30, 2021
- Raw hash
- a8089e96014f8dc18594afd532e181ec8d692af5eee779cf4efb8666e0ae0504
Reporting entity
- Name
- Bansley and Kiener, LLPnorm: bansley and kiener
- Domain
- bk-cpa.com
Victim entity
- Name
- Bansley and Kiener, LLPnorm: bansley and kiener
- Domain
- bk-cpa.com
Incident
- Discovered
- Dec 10, 2020
- Materiality determined
- Aug 24, 2021
- Notification sent
- Aug 24, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 51 weeks(355 days from discovery to filing)
- Compliance flags
- CA 60-day late · 257d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 10, 2020→ Notified: Aug 24, 2021257d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.