Mendes & Haney, LLP, a California law firm, disclosed a data breach involving unauthorized access to its network via Remote Desktop Protocol (RDP) from a foreign IP address between January 23, 2018, and February 26, 2018. The incident was discovered on February 28, 2018, following a rejected tax return. The breach exposed client PII, including SSNs, names, addresses, and financial/bank account information. The firm engaged forensic investigators, notified law enforcement (FBI, IRS, FTB), and offered credit monitoring and identity theft protection services to affected individuals.