Hoplon InfoSec Logo

Hoplon Infosec · Threat Intelligence

Eisner Advisory Group Data Breach: What You Must Know

ByHoplon Infosec
Published02 Aug, 2026
Eisner Advisory Group Data Breach: What You Must Know
Hoplon Infosec02 Aug, 2026

Eisner Advisory Group Data Breach: What You Must Know

If a letter from Eisner Advisory Group just landed in your mailbox, your first reaction was probably confusion mixed with a bit of dread. That reaction is fair. A company that handles sensitive financial and personal records got broken into by an unknown outsider back in September 2023, and it took the firm well over a year to figure out exactly whose information was touched.

The letters finally went out in April 2025. Below is a fast reference table so you can see the core facts in one glance before we walk through everything in detail.

DetailInformation
Company involvedEisner Advisory Group LLC, operating under the EisnerAmper brand
Unauthorized access windowSeptember 4, 2023 to September 9, 2023
Discovery dateSeptember 2023, with a full forensic review completed February 13, 2025
Notification letters mailedApril 8, 2025
People affectedApproximately 84,795 individuals nationwide
Data exposedFull name, address, Social Security number, driver license or state ID, passport number, date of birth, financial account details, payment card data, and in some cases medical or health insurance information
Assistance line1 877 782 4279 (Monday to Friday, 9 am to 9 pm Eastern)
Free offer to victimsComplimentary credit monitoring enrollment

What Actually Happened Inside Eisner Advisory Group

Eisner Advisory Group is not a small local shop. It operates under the much larger EisnerAmper umbrella, a professional services firm with thousands of employees and hundreds of millions in yearly revenue, offering audit, tax, and business advisory work to a huge client base across the country.

That scale is exactly why this event matters so much. When a firm this large stores names, Social Security numbers, medical records, and financial account details for tens of thousands of clients, a break in its defenses does not stay small.

According to the company's own account and multiple state attorney general filings, someone outside the organization managed to slip into internal systems for a short window between September 4 and September 9 of 2023. The company noticed something was off almost immediately and shut the intrusion down. That part sounds reassuring. What comes next is the part people find frustrating.

Why Did It Take So Long to Tell People

Here is where the timeline gets uncomfortable for anyone affected. The intrusion happened in September 2023, yet the notification letters were not mailed until April 8, 2025. That is a gap of roughly a year and a half. Regulators and class action attorneys have asked the same question everyone reading this is probably asking right now. Why so long?

The honest answer, based on the firm's own review completed on February 13, 2025, comes down to the messy nature of stolen files. When attackers pull data out of a network, they rarely grab a neat spreadsheet with clear labels. Instead they often walk away with a jumble of documents, scanned forms, email attachments, and free form files that have no consistent structure.

Investigators then have to manually or semi automatically sift through every single file to identify which specific person's name, number, or record appears where. For a firm handling client data across accounting, tax, and advisory services, that process took months of dedicated forensic work before Eisner could even say with confidence who was impacted and what exactly was exposed.

It is a slow and tedious process, but it is also the reason the eventual notice was accurate rather than a rushed guess.

The Data That Was Exposed

Not every data breach is equally dangerous. Some only expose an email address, which is annoying but rarely life altering. This one is different because of the depth of information involved. Based on notifications filed with multiple state regulators, the categories of exposed data include the following.

  • Full legal name and home address
  • Social Security number
  • Driver license number or other state issued identification number
  • Passport number
  • Date of birth
  • Financial account information
  • Payment card numbers
  • Medical information and health insurance details for a portion of affected individuals

Put together, this is close to a complete identity kit. A Social Security number combined with a date of birth and address is often enough on its own to open a fraudulent credit line, file a fake tax return in someone's name, or pass identity checks with a bank. Add a driver license number or passport number and criminals gain the ability to create convincing fake identification.

Add financial account or payment card data and the risk moves from long term identity fraud into immediate account takeover territory. Medical information adds yet another layer, since health records can be used for insurance fraud or targeted scams that reference real diagnoses or treatments to sound convincing.

How to Find Out If You Are One of the 84,795

Eisner Advisory Group reported that approximately 84,795 people across the United States were affected. If your data was involved, the company was required by law to mail you a written notice describing exactly what categories of your personal information were exposed.

If you already received that letter, keep it somewhere safe. It is proof of the incident and may matter later if you decide to pursue any compensation or need to prove identity theft resulted directly from this event.

If you worked with Eisner Advisory Group or EisnerAmper in any capacity, whether through tax preparation, audit work, or business advisory services, and you have not received a letter but are unsure, you can call the dedicated assistance line at 1 877 782 4279, available Monday through Friday from 9 am to 9 pm Eastern time. You can also reach the firm by mail at Attn Partner in Charge, 2501 S Wayzata Blvd, Minneapolis, MN 55405.

Eisner Advisory Group Data Breach What You Must Know



Your Immediate Action Plan, Step by Step

Whether you have already received a letter or you simply want to be careful, here is the order of operations that actually protects you, explained in plain language rather than legal jargon.

Step 1: Understand the Difference Between a Fraud Alert and a Credit Freeze

A fraud alert is a lightweight tool. It tells lenders to take extra verification steps before opening new credit in your name. A standard fraud alert lasts one year, though confirmed identity theft victims can request an extended alert that lasts seven years. It is easy to set up and free.

A credit freeze is the stronger option. Once active, it locks your credit file so tightly that no lender can even view it to approve new credit, which means a thief cannot open a new account in your name even if they have your Social Security number in hand. You can freeze and unfreeze it yourself whenever you actually need to apply for credit.

For a breach this serious, involving SSNs, dates of birth, and government ID numbers, a full credit freeze is the safer route rather than relying on an alert alone.

Step 2: Contact All Three Credit Bureaus

You need to freeze your file with all three bureaus separately, since each one keeps an independent record.

BureauPhoneMailing Address
Equifax1 888 298 0045P.O. Box 105788, Atlanta, GA 30348
Experian1 888 397 3742P.O. Box 9554, Allen, TX 75013
TransUnion1 833 395 6938P.O. Box 160, Woodlyn, PA 19094

Step 3: Gather Your Documents Before You Call

To place a freeze or dispute fraudulent activity, bureaus typically ask for the following, so have them ready.

  • Full legal name, including any suffix such as Jr, Sr, or III
  • Social Security number and date of birth
  • Two to five years of address history
  • A current proof of address such as a utility or phone bill
  • A copy of a government issued photo ID
  • A police report or identity theft complaint copy, if you already filed one

Step 4: Pull Your Free Credit Reports and Watch Them Closely

Every consumer is entitled to a free credit report from each bureau through annualcreditreport.com or by calling 1 877 322 8228. After a breach of this size, do not treat this as a once a year chore.

Pull your reports now, then check back regularly over the following months and watch for accounts, inquiries, or addresses that you do not recognize.

Know Your Rights Depending on Where You Live

Data breach laws are not identical in every state, and a few states give extra protections worth knowing about.

  • Massachusetts residents have a specific legal right to obtain a copy of any related police report.
  • Residents of the District of Columbia can contact the Attorney General's office at oag@dc.gov or 1 202 727 3400.
  • Maryland residents can reach their AG office at 1 888 743 0023.
  • New Mexico residents have rights under the Fair Credit Reporting Act, including the right to know their credit score, the right to correct inaccurate information, and the right to pursue legal damages in certain cases.
  • New York residents can contact the Attorney General at 1 800 771 7755.
  • North Carolina residents can reach the AG office at 1 877 566 7226.
  • Rhode Island reported 53 affected residents and those individuals retain specific legal protections along with the right to obtain a police report.

If You Suspect Identity Theft, Escalate to the Federal Trade Commission

If you notice suspicious activity tied to your identity after this breach, the Federal Trade Commission is the right place to file an official complaint and generate a personalized recovery plan.

  • Portal: identitytheft.gov
  • Phone: 1 877 438 4338, TTY 1 866 653 4261
  • Mail: Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, DC 20580

Filing through identitytheft.gov gives you an official recovery plan and a report you can use with creditors, banks, and credit bureaus if you need to prove that fraudulent activity traces back to identity theft rather than your own error.

Official Reference for This Incident

You can review the original consumer notice that Eisner Advisory Group filed with a state regulator directly through the Vermont Attorney General's official breach notice filing, which is a public government record confirming the incident, the timeline, and the categories of exposed data described in this article.

Frequently Asked Questions

Why did Eisner Advisory Group take over a year to notify affected people?

The delay came from the forensic review process. Stolen files were not neatly organized, so investigators had to manually sort through unstructured documents to confirm exactly whose data appeared and in what form. That review finished on February 13, 2025, and letters followed on April 8, 2025.

Will freezing my credit affect my current credit cards or loans?

No. A credit freeze only blocks new credit applications and inquiries. Any account you already hold continues working exactly as before. You only need to temporarily lift the freeze if you plan to apply for new credit.

Is Eisner Advisory Group offering free credit monitoring?

Yes. Affected individuals are being offered complimentary credit monitoring enrollment as part of the company's response to the breach.

How do I know a notice claiming to be from Eisner is real and not a phishing attempt?

Verify it against the official assistance line, 1 877 782 4279, and the official mailing address at 2501 S Wayzata Blvd, Minneapolis, MN 55405. Never click links or call numbers printed in unsolicited emails or texts claiming to be from Eisner. Go directly to the verified contact details instead.

What information specifically was exposed in the Eisner Advisory Group data breach?

Names, addresses, Social Security numbers, driver license or state ID numbers, passport numbers, dates of birth, financial account information, payment card numbers, and for some individuals, medical information and health insurance details.

Wrap Up

A breach involving Social Security numbers, government ID numbers, and financial data is not something to shrug off. The good news is that the response does not need to be complicated. Freeze your credit with all three bureaus, pull your free reports and actually read them, keep the official notification letter somewhere safe, and stay alert for any communication pretending to be from Eisner that asks for information over the phone or by email.

Identity thieves are patient and they often wait months before acting on stolen data, so ongoing vigilance matters more than a single one time check. Taking these steps now puts you back in control of your own information.

Related Reading From Hoplon Infosec

If you want to understand how this fits into the wider pattern of professional services firms getting hit by data breaches, these related breakdowns from Hoplon Infosec are worth a look.

Was this useful?

React, leave a note, or share it forward.

Leave a note

Share this article

Share this :

03Latest posts

Free · Weekly · No noise

Get the threats that matter, before they reach you.

One short email a week with the breaches, zero-days, and fixes worth your attention — written in plain English, no fear-mongering.