Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Top US Accounting Firm Sax Discloses 2024 Data Breach Impacting 220,000

It took Sax well over a year to complete its investigation after detecting hackers on its network.

Data breach

Sax LLP, a top-ranked US accounting firm, has begun notifying over 220,000 individuals that sensitive personal data was compromised in a cyberattack that went undisclosed for more than 16 months.

Based in New Jersey, Sax is a top 100 accounting and advisory company with an annual revenue exceeding $100 million.

In a filing with the Maine Attorney General’s Office, Sax revealed that it had detected a network intrusion on August 7, 2024. However, it took the company well over a year to complete its investigation and identify contact information for the impacted individuals.

The probe showed that hackers likely gained access to its systems in late July 2024 and managed to obtain files containing the personal information of 228,876 individuals.

According to Sax, the compromised information varies for each individual, but can include name, date of birth, SSN, driver’s license or state identification number, and passport number. 

SecurityWeek has not seen any known ransomware group take credit for an attack on Sax. It’s possible that the company was targeted by cybercriminals who do not have a public leak website, or the firm may have paid a ransom to prevent the data from being made public or distributed to others.

Advertisement. Scroll to continue reading.

The company is offering impacted individuals 12 months of free credit monitoring, dark web monitoring, credit protection, and identity restoration services. 

However, the significant delay in notifying victims renders these services functionally obsolete because cybercriminals typically monetize stolen information within the first few months following the breach. 

Related: Coupang to Issue $1.17 Billion in Vouchers Over Data Breach

Related: 22 Million Affected by Aflac Data Breach

Related: Hacker Claims Theft of 40 Million Condé Nast Records After Wired Data Leak

Related: 3.5 Million Affected by University of Phoenix Data Breach

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.