Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
ID: d47e9a31-228e-5e52-bac5-83decd87634d
STIX ID: report--d47e9a31-228e-5e52-bac5-83decd87634d
Feed Name: DataBreaches.Net
Wojeski & Company experienced a July 28, 2023 ransomware attack caused by a phishing email and a separate May 31, 2024 incident in which a contractor improperly accessed and exfiltrated client data; together the breaches exposed highly sensitive PII (including SSNs, dates of birth, driver’s license numbers, financial account information and medical benefits) for 6,232 individuals (4,993 New York residents). The firm delayed notifying victims until November 2024, offered one year of credit monitoring, and settled with the New York Attorney General for $60,000 while agreeing to implement stricter security controls, encryption, inventorying of stored data, account management, vulnerability remediation, incident response, and mandatory employee cybersecurity training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
