CSIDB logo
Incident

Harding, Shymanski & Company

Incident posture

Attack window
Mar 2023
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-11 00:00

Linked entities

Victim
Harding, Shymanski & Company
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

An accounting firm experienced a data breach after an unauthorized party compromised an employee's credentials to access clients' 2021 tax returns and sensitive files, resulting in the filing of fraudulent tax returns for some individuals. The breach exposed personally identifiable and financial information, including names, Social Security numbers, dates of birth, driver's license details, and banking or investment account data. The firm secured its network, engaged cybersecurity specialists and law enforcement, and notified affected individuals following its investigation. The incident impacted clients across multiple industries served by the organization, posing risks of financial fraud and identity theft.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 15, 2023, Harding, Shymanski & Company (HSC) discovered that several clients had fraudulent tax returns filed in their names, prompting an immediate response. The firm secured its network, notified law enforcement, and engaged third-party cybersecurity experts to investigate the incident. The investigation revealed that an unauthorized party had compromised a single employee’s credentials, using them to access 2021 tax returns and other files containing sensitive client data. This breach exposed personal information, including names, dates of birth, Social Security numbers, driver’s license numbers, bank account and routing numbers, and investment or brokerage account details. By March 27, 2023, HSC completed its review of affected files to identify the compromised information and impacted individuals. The incident directly affected clients who had utilized HSC’s accounting or tax preparation services, with confirmed cases of fraudulent activity already reported by some victims.

On April 11, 2023, HSC filed a formal notice with the Montana Attorney General and began mailing data breach notifications to all affected individuals. The firm did not disclose the total number of impacted clients or the exact method of initial credential compromise. Founded in 1975 and operating primarily in Kentucky and Indiana, HSC serves clients across multiple industries, including construction, healthcare, and manufacturing. The breach compromised data essential to identity theft and financial fraud, creating risks for unauthorized tax filings and potential misuse of banking or brokerage details. HSC’s response focused on containment, external collaboration, and regulatory compliance, though the breach underscores vulnerabilities in credential management and tax document security. The incident disrupted client trust and necessitated ongoing vigilance against fraud for those whose data was exposed.

Sources

Sources available to members: 1 source.

CSIDB