DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Attorney General James Announces Settlement with Wojeski & Company Accounting Firm

Posted on October 21, 2025October 21, 2025 by Dissent
Wojeski & Company suffered a ransomware attack, and then an insider breach when an employee of a firm hired to investigate the breach inappropriately accessed data. Employees were also transmitting data to external accounts without authorization. To make things even worse, the accounting firm took more than a year to notify those affected. From a press release from the NY Attorney General’s Office:

October 20, 2025

NEW YORK – New York Attorney General Letitia James today announced a settlement with a public accounting firm, Wojeski & Company (Wojeski), to strengthen its data security to protect consumers’ data. Wojeski did not take proper measures to secure their clients’ personal information and suffered two cybersecurity incidents that exposed the private information of more than 4,700 New Yorkers. An investigation by the Office of the Attorney General (OAG) found that Wojeski took over a year to notify victims of the data breach, despite being required to notify victims soon after a breach. As a result of today’s agreement, Wojeski must pay $60,000 in penalties and take steps to improve its cybersecurity measures. Individuals who were affected by the data breaches were offered one year of free credit report monitoring.

“Ransomware attacks like the ones at Wojeski put consumers at risk,” said Attorney General James. “As an accounting firm, Wojeski should have taken stronger measures to protect New Yorkers’ personal data and prevent data breaches that could lead to identity theft and other types of fraud. When New Yorkers pay for a service, they should trust that the company they are paying will not expose their private information. Companies must do more to protect their customers’ data and my office will not hesitate to hold them to account.”

Wojeski is a certified public accounting firm. On July 28, 2023, Wojeski employees realized they were experiencing a ransomware attack when they were unable to access certain files in their systems. After containing the threat and launching an investigation, Wojeski found that the cyberattack was likely caused by a phishing email sent to one of their employees. The investigation also found that customers’ social security numbers were not encrypted in parts of the company’s network. On May 31, 2024, Wojeski was notified of another data breach when an employee from a firm hired to help with the investigation improperly accessed customer data located in the files that Wojeski had sent for review. The employees were also sending the information to several external email addresses without authorization.

Wojeski did not notify customers of either security breach until November 2024, a year and a half after their clients’ personal data was first jeopardized. Personal data exposed in one or both incidents included names, dates of birth, social security numbers, drivers’ license numbers, email addresses, phone numbers, financial account numbers, medical benefits, and entitlement information. The 2023 data breach affected 5,881 individuals, 4,726 of whom were New York residents, and the 2024 breach affected a total of 351 individuals, 267 of whom were New York residents. Following the data breaches, Wojeski offered impacted individuals free credit monitoring.

As a result of today’s agreement, Wojeski will pay $60,000 in penalties and the company is required to adopt stricter security standards to better protect the personal information of its customers in the future, including:

  • Maintaining a comprehensive information security program to protect the security, integrity, and confidentiality of customer information;
  • Encrypting personal information that the company collects, stores, transmits, and/or maintains;
  • Developing and maintaining an inventory of where personal data is being stored within its network;
  • Maintaining reasonable account management and authentication processes that limit employees’ access to sensitive information as necessary;
  • Establishing a program designed to identify and correct security vulnerabilities within its computer network;
  • Implementing an incident response plan ensuring timely notice to consumers; and
  • Implementing a cybersecurity training program to be completed by all employees.

Source: New York Attorney General Letitia James

The state does not seem to have uploaded the agreement and terms Wojeski accepted.

Category: Business SectorMalwareOf NotePhishingU.S.

Post navigation

← Romanian prisoner hacks prison IT system in plot made for a Netflix movie
Cyber-Attack On Bectu’s Parent Union Sparks UK National Security Concerns →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says
  • The Case for Making EdTech Companies Liable Under FERPA
  • NHS providers reviewing stolen Synnovis data published by cyber criminals

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.