Social EngineeringPhishingRansom DemandedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Anthony & Dodge PC
bd_e7a8205c7e2d32fc · schema v1 · pii pii-v1
Full breach record for Anthony & Dodge PC →Anthony & Dodge PC notified consumers of a data breach occurring Feb 21-22, 2025. An employee clicked a malicious link in a video conference invitation, allowing an external actor to access client tax files via CCH Access. The actor filed fraudulent tax returns. Affected data includes names, SSNs, and financial account info. The firm engaged forensic experts, notified the IRS and FBI, and is offering credit monitoring.
Vermont clock✗ VT AG >45 bday10 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_19f63777e2969f41New Hampshire State AGfiled 2025-05-01(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-04-30-anthony-dodge-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 30, 2025
- Raw hash
- a5bffd3c4a2692d2e022a8fb184120385d6017615a7a01215d031d0b85246309
Reporting entity
- Name
- Anthony & Dodge PCnorm: anthony dodge
Victim entity
- Name
- Anthony & Dodge PCnorm: anthony dodge
Incident
- Discovered
- Feb 21, 2025
- Materiality determined
- Apr 30, 2025
- Notification sent
- Apr 30, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Contacted the cybersecurity division of the Internal Revenue Service (IRS)Filed a report with the Federal Bureau of Investigations (FBI)
- Initial access
- phishing_link
Compliance
- Time to disclose
- 10 weeks(68 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.