DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDFinancialMediumActive

Baylor Evnen, LLP

bd_fd2ba4a7fde37ac5 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 3, 2020

Filed

Apr 20, 2020

To disclose

17 days

Affected

1state residents only

Confidence

65%
Full breach record for Baylor Evnen, LLP

Baylor Evnen, LLP notified Montana AG of an email spoofing attack on April 3, 2020. Attackers impersonated an employee to obtain 2019 W-2 forms from current/former 2019 employees. Data exposed included names, addresses, SSNs, and wages. The firm engaged Kroll for 12 months of identity protection, notified the FBI and IRS, and is assessing IT systems.

Incident timeline

discovery → filing · 17 days

Apr 3, 2020

Begins

Apr 3, 2020

Discovered

Apr 20, 2020

Filed

vs. sector median

15 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.