Overview
On January 21, 2025, New York Attorney General Letitia James announced a $60,000 settlement with Wojeski & Company, CPAs, P.C., a Rochester-based accounting firm, following a data security incident that exposed personal information of approximately 195,000 individuals.
Incident Details
Timeline
- November 2022: Breach occurred
- March 2024: Affected individuals notified (16-month delay)
- January 2025: Settlement announced
Attack Vector
The breach was initiated through a phishing email that infiltrated the firm's network. This social engineering attack led to unauthorized access to sensitive client data stored on the firm's systems.
Data Compromised
The breach potentially exposed:
- Social Security numbers
- Driver's license numbers
- Financial account information
- Tax return data
- Other personal identifying information
Security Failures Identified
Critical Violations
- Unencrypted Data Storage: Failed to encrypt personal information at rest
- Delayed Notification: 16-month gap between breach and notification
- Inadequate Access Controls: Insufficient authentication mechanisms
- Missing Security Policies: Lack of comprehensive data protection procedures
- Insufficient Employee Training: Limited security awareness training
Legal Requirements Violated
The investigation found violations of:
- New York General Business Law § 899-aa: Requires reasonable security measures for private information
- New York General Business Law § 899-bb: Mandates timely breach notifications
Settlement Terms
Financial Penalty
$60,000 total penalty to New York State
Required Actions
Wojeski & Company must implement the following measures:
- Encryption: Implement encryption for personal information at rest and in transit
- Multi-Factor Authentication: Deploy MFA across all systems handling personal data
- Access Controls: Implement role-based access controls and principle of least privilege
- Security Training: Conduct regular employee security awareness training
- Incident Response Plan: Develop and maintain a comprehensive incident response plan
- Regular Audits: Conduct periodic security assessments and vulnerability scans
- Vendor Management: Establish third-party risk management procedures
- Data Minimization: Retain personal information only as long as necessary
Official Statement
"When companies experience a data breach, they must act immediately to inform consumers so they can take steps to protect themselves. Wojeski & Company not only failed to adequately protect New Yorkers' personal information, but also failed to alert New Yorkers in a timely manner, leaving them vulnerable to identity theft and fraud."
Lessons for Organizations
Key Compliance Takeaways
- Encryption is Mandatory: Encrypt all personal data, especially at rest
- Time Matters: Breach notifications must be timely (typically within 72 hours to relevant authorities)
- Defense in Depth: Implement multiple layers of security controls
- Human Factor: Phishing remains a top threat—training is essential
- Regulatory Scrutiny: State AGs are actively enforcing data protection laws
- Documentation Required: Maintain evidence of security measures and incident response
Industry Impact
This case is particularly significant for:
- Professional Services Firms: Accounting, legal, and consulting firms handling sensitive client data
- Small to Mid-Sized Businesses: Demonstrates that size doesn't exempt from compliance requirements
- Organizations in New York: Reinforces aggressive enforcement of state data protection laws
Compliance Resources
About This Series
Breach Watch is our ongoing series tracking data breach settlements, enforcement actions, and regulatory penalties. We analyze each case to extract actionable compliance insights for organizations of all sizes.
Stay informed. Stay protected. Stay compliant.
Source: NY Attorney General Press Release
Date: January 21, 2025