HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICLowContained
SAX
bd_db6dcf921571714a · schema v1 · pii pii-v1
Full breach record for SAX →Sax, LLP notified South Carolina residents of a security incident detected on August 7, 2024. Unauthorized access to the firm's environment resulted in the potential exposure of names and other personal information. Sax engaged cybersecurity experts, notified the FBI, and implemented additional security measures. Affected individuals were offered complimentary credit and identity monitoring services through Epiq.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_03368ea6c198e1b3Montana State AGfiled 2025-12-22(1d gap)Verified
- bd_6b0331732b1d6680Maine State AGfiled 2025-12-22(1d gap)Verified
- bd_70f3b36fdd6d270fNew Hampshire State AGfiled 2025-12-22(1d gap)Verified
- bd_a57bf44b11d3263aCalifornia State AGfiled 2025-12-22(1d gap)Candidate
Show 4 more filings ↓Show fewer ↑up to 7d gap
- bd_ce441aca74d4f237Vermont State AGfiled 2025-12-22(1d gap)Verified
- bd_1ef0f101196477a7Texas State AGfiled 2025-12-29(6d gap)Verified
- bd_556c3ae504f7e82cDelaware State AGfiled 2025-12-16(7d gap)Verified
- bd_a0269a5e4239280fIndiana State AGfiled 2025-12-16(7d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Consumer%20Letter%20-%20Sax%2C%20LLP.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2025
- Raw hash
- 90522a36adf7809bbcab452060005a7fb36ed18da9c761a3774fc8de5625cf0e
Reporting entity
- Name
- SAXnorm: sax
- Domain
- saxadvisorygroup.com
Victim entity
- Name
- SAXnorm: sax
- Domain
- saxadvisorygroup.com
Incident
- Discovered
- Aug 7, 2024
- Materiality determined
- —
- Notification sent
- Dec 1, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 months(503 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.