Ondracek & Company, a CPA firm, disclosed a data breach involving unauthorized access via Remote Desktop Protocol (RDP) from a foreign IP address between November 21, 2016, and February 6, 2017. The incident exposed client PII, including SSNs, DOBs, and financial account details. The company engaged forensic investigators, notified the FBI, IRS, and state agencies, and provided 24 months of credit monitoring to affected individuals.