CSIDB logo
Incident

Walters McCann Fanska

Incident posture

Attack window
Dec 2014
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-16 22:03

Linked entities

Victim
Walters McCann Fanska
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

An accounting firm experienced unauthorized network access by hackers over several months, potentially compromising clients' personal and financial account information. Suspicious activity involving some accounts prompted the firm to engage forensic investigators, who confirmed a security breach; while no evidence confirmed data access occurred, the organization notified affected clients and offered complimentary credit monitoring services for two years as a precautionary measure.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In late February 2015, Walters McCann Fanska, a Kansas City-based accounting firm, detected suspicious activity involving client accounts on its network. The firm promptly engaged a forensic investigator to examine the incident. On March 4, 2015, the investigation confirmed unauthorized access to the firm’s network systems, with the compromise period extending from late 2014 through late February 2015. While forensic analysis could not confirm whether hackers actually accessed or exfiltrated specific client data during this intrusion window, the firm determined that attackers potentially acquired personal and financial account information belonging to clients. The breach timeline indicated continuous network access by threat actors for approximately three months before detection.

Walters McCann Fanska initiated client notifications following the forensic confirmation, disclosing the possibility of data exposure despite lacking definitive evidence of information misuse. The firm referenced observable suspicious account activity in its disclosure but did not specify the number of affected individuals or clients. As a remedial measure, the accounting practice offered impacted clients two years of credit monitoring and identity protection services through Experian. Notification letters were filed with the Vermont Attorney General’s office, though the firm’s client base geographic scope remained unspecified in available documentation. No operational disruptions or system downtime were reported in conjunction with the security incident.

Sources

Sources available to members: 1 source.

CSIDB