MalwareRansomwareData ExfiltratedData EncryptedRansom DemandedRansom PaidSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICLowContained
Perkins & Co.
bd_ea38731c50620c8e · schema v1 · pii pii-v1
Full breach record for Perkins & Co. →Perkins & Co, a Portland-based accounting firm, notified Delaware AG of a ransomware incident involving third-party vendor Netgain. Between Nov 8 and Dec 3, 2020, attackers accessed, encrypted, and exfiltrated client files. Netgain paid the ransom and recovered files. The breach exposed client names and variable data elements. Perkins reported to the IRS and state authorities, offered credit monitoring, and Netgain implemented enhanced security controls.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_d8abad6eabb79ff8California State AGfiled 2022-05-27Candidate
- bd_f2d5e0dbc45e8b31Oregon State AGfiled 2022-05-27Verified
- bd_ba5d30aabab3a141Delaware State AGfiled 2022-05-26(1d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/06/Pages-from-Perkins-Initial-Notice-of-Data-Event-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 27, 2022
- Raw hash
- f1e3dcdf3eeff04125cfb550a6bbcbfc8b9417bbfde0b4ac08a3f21f3fd85946
Reporting entity
- Name
- Perkins & Co.norm: perkins
- Domain
- perkinsaccounting.com
Victim entity
- Name
- Perkins & Co.norm: perkins
- Domain
- perkinsaccounting.com
Incident
- Discovered
- Dec 3, 2020
- Materiality determined
- —
- Notification sent
- May 25, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 ChannelT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to the IRS and state tax authorities, as well as applicable state data privacy regulatory authorities
- Initial access
- supply_chain
Compliance
- Time to disclose
- 18 months(540 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.