
Platt, Miller & Jacobs, CPAs, LLP, a Santa Cruz, California CPA firm that has served businesses, individuals and non-profits since 1938, disclosed a data breach that may have exposed sensitive client information.
On March 10, 2026, an unauthorized user gained access to an employee's Microsoft Outlook email account at Platt, Miller & Jacobs. The threat actor used the compromised account to send phishing emails to some of the firm's clients.
The firm discovered the unauthorized access the following day, on March 11, 2026. It launched an investigation with the help of third-party IT specialists to determine the full nature and scope of the incident.
The investigation found that sensitive personal information stored in the compromised email account was accessible to the threat actor. However, the firm stated that the threat actor did not have access to any part of its tax return or file storage systems.
The types of information that may have been exposed included dates of birth, Social Security numbers, addresses, email addresses, phone numbers, financial account information, driver's license numbers, state identification numbers and credit or debit card numbers.
The breach was disclosed to the Massachusetts Office of Consumer Affairs and Business Regulation on Sept. 28, 2026. The firm mailed notification letters to affected individuals on Sept. 28, 2026.
The firm is offering affected individuals 18 months of free identity monitoring services through Kroll. The services include single bureau credit monitoring, unlimited fraud consultation with a Kroll specialist and identity theft restoration assistance from a licensed investigator.
Affected individuals can enroll by visiting the Kroll enrollment portal and entering the membership number included in their notification letter. For questions or concerns, individuals can reach Kroll at 844-958-8948, Monday through Friday from 8 a.m. to 5:30 p.m. Central Time, excluding U.S. holidays.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)