DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Attorney General James Announces Settlement with Wojeski & Company Accounting Firm

Posted on October 21, 2025October 21, 2025 by Dissent
Wojeski & Company suffered a ransomware attack, and then an insider breach when an employee of a firm hired to investigate the breach inappropriately accessed data. Employees were also transmitting data to external accounts without authorization. To make things even worse, the accounting firm took more than a year to notify those affected. From a press release from the NY Attorney General’s Office:

October 20, 2025

NEW YORK – New York Attorney General Letitia James today announced a settlement with a public accounting firm, Wojeski & Company (Wojeski), to strengthen its data security to protect consumers’ data. Wojeski did not take proper measures to secure their clients’ personal information and suffered two cybersecurity incidents that exposed the private information of more than 4,700 New Yorkers. An investigation by the Office of the Attorney General (OAG) found that Wojeski took over a year to notify victims of the data breach, despite being required to notify victims soon after a breach. As a result of today’s agreement, Wojeski must pay $60,000 in penalties and take steps to improve its cybersecurity measures. Individuals who were affected by the data breaches were offered one year of free credit report monitoring.

“Ransomware attacks like the ones at Wojeski put consumers at risk,” said Attorney General James. “As an accounting firm, Wojeski should have taken stronger measures to protect New Yorkers’ personal data and prevent data breaches that could lead to identity theft and other types of fraud. When New Yorkers pay for a service, they should trust that the company they are paying will not expose their private information. Companies must do more to protect their customers’ data and my office will not hesitate to hold them to account.”

Wojeski is a certified public accounting firm. On July 28, 2023, Wojeski employees realized they were experiencing a ransomware attack when they were unable to access certain files in their systems. After containing the threat and launching an investigation, Wojeski found that the cyberattack was likely caused by a phishing email sent to one of their employees. The investigation also found that customers’ social security numbers were not encrypted in parts of the company’s network. On May 31, 2024, Wojeski was notified of another data breach when an employee from a firm hired to help with the investigation improperly accessed customer data located in the files that Wojeski had sent for review. The employees were also sending the information to several external email addresses without authorization.

Wojeski did not notify customers of either security breach until November 2024, a year and a half after their clients’ personal data was first jeopardized. Personal data exposed in one or both incidents included names, dates of birth, social security numbers, drivers’ license numbers, email addresses, phone numbers, financial account numbers, medical benefits, and entitlement information. The 2023 data breach affected 5,881 individuals, 4,726 of whom were New York residents, and the 2024 breach affected a total of 351 individuals, 267 of whom were New York residents. Following the data breaches, Wojeski offered impacted individuals free credit monitoring.

As a result of today’s agreement, Wojeski will pay $60,000 in penalties and the company is required to adopt stricter security standards to better protect the personal information of its customers in the future, including:

  • Maintaining a comprehensive information security program to protect the security, integrity, and confidentiality of customer information;
  • Encrypting personal information that the company collects, stores, transmits, and/or maintains;
  • Developing and maintaining an inventory of where personal data is being stored within its network;
  • Maintaining reasonable account management and authentication processes that limit employees’ access to sensitive information as necessary;
  • Establishing a program designed to identify and correct security vulnerabilities within its computer network;
  • Implementing an incident response plan ensuring timely notice to consumers; and
  • Implementing a cybersecurity training program to be completed by all employees.

Source: New York Attorney General Letitia James

The state does not seem to have uploaded the agreement and terms Wojeski accepted.

Category: Business SectorMalwareOf NotePhishingU.S.

Post navigation

← Romanian prisoner hacks prison IT system in plot made for a Netflix movie
Cyber-Attack On Bectu’s Parent Union Sparks UK National Security Concerns →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Fourth Circuit Weighs in on Standing in Data Breach Class Actions
  • ALT5 Sigma sues former consultant over alleged data breach
  • Is your cyberinsurance paid up? Are you sure?
  • Everest Group Interview on Collins Aerospace Breach — Daily Dark Web
  • Breaking Up With Edtech Is Hard to Do
  • Benworth Capital Partners negotiated with threat actors after more than 25,000 lenders had data stolen
  • Android Hit by 0-Click RCE Vulnerability in Core System Component
  • Attorney General James and Multistate Coalition Secure $5.1 Million from Illuminate Education For Failing to Protect Students’ Data
  • The Congressional Budget Office was hacked. It says it has implemented new security measures.
  • Clop Ransomware group claims the breach of The Washington Post

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Modern cars are spying on you. Here’s what you can do about it.
  • Attorney General James and Multistate Coalition Secure $5.1 Million from Education Software Company for Failing to Protect Students’ Data       
  • EU Parliament committee votes to advance controversial Europol data sharing proposal
  • DHS offers “disturbing new excuses” to seize kids’ biometric data, expert says
  • California Adds Injunctive Relief to its Right of Publicity Statute and Extends Liability to Digital Replicas

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.