HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Andrew Lundholm CPA
bd_db90b5d792895b18 · schema v1 · pii pii-v1
Full breach record for Andrew Lundholm CPA →Andrew Lundholm CPA reported a data breach affecting tax filing software between November 24, 2019, and April 29, 2020. An unknown actor accessed folders containing sensitive client information, including names, addresses, dates of birth, Social Security numbers, and financial account numbers. The company engaged forensic specialists, notified the IRS and state regulators, and offered 12 months of credit monitoring and identity protection services to affected individuals.
California clockDiscovered Apr 29, 2020 → Notified Jul 1, 202063d ✗ CA 60-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-191602
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2020
- Raw hash
- a5d3cb95aec9a7335f58e5e2270a941a7abade02f7d1a39aafb9f53bb1edaded
Reporting entity
- Name
- Andrew Lundholm CPAnorm: andrew lundholm cpa
- Domain
- aclcpa.net
Victim entity
- Name
- Andrew Lundholm CPAnorm: andrew lundholm cpa
- Domain
- aclcpa.net
Incident
- Discovered
- Apr 29, 2020
- Materiality determined
- —
- Notification sent
- Jul 1, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the event to the IRSreported the incident to certain state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(63 days from discovery to filing)
- Compliance flags
- CA 60-day late · 63d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 29, 2020→ Notified: Jul 1, 202063d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.