Sax’s 16-Month Cyber Snafu: Delayed Alert Leaves 220,000 Vulnerable to Data Breach Disaster
Sax LLP, a top-ranked US accounting firm, is notifying over 220,000 individuals of a data breach that went unnoticed for 16 months. Hackers accessed personal information, but Sax’s timely response was only a year and a half late. Free credit monitoring is offered, but cybercriminals have likely already been busy.

Hot Take:
It seems Sax LLP has taken the ‘slow and steady’ approach to a whole new level — because who doesn’t love a good surprise 16 months later? If procrastination were an Olympic sport, Sax just snagged the gold. But in all seriousness, giving hackers a head start is one race you don’t want to win.
Key Points:
- Sax LLP, a top 100 accounting firm, disclosed a data breach affecting 228,876 individuals.
- The breach was detected in August 2024 but went undisclosed for over 16 months.
- Sensitive information like SSNs, driver’s license numbers, and passport numbers were compromised.
- There is no known ransomware group claiming responsibility, raising suspicions of a quiet ransom payment.
- Sax is offering 12 months of credit and identity protection services, albeit long after the breach.
Already a member? Log in here
