
If a letter from Eisner Advisory Group just landed in your mailbox, your first reaction was probably confusion mixed with a bit of dread. That reaction is fair. A company that handles sensitive financial and personal records got broken into by an unknown outsider back in September 2023, and it took the firm well over a year to figure out exactly whose information was touched.
The letters finally went out in April 2025. Below is a fast reference table so you can see the core facts in one glance before we walk through everything in detail.
| Detail | Information |
|---|---|
| Company involved | Eisner Advisory Group LLC, operating under the EisnerAmper brand |
| Unauthorized access window | September 4, 2023 to September 9, 2023 |
| Discovery date | September 2023, with a full forensic review completed February 13, 2025 |
| Notification letters mailed | April 8, 2025 |
| People affected | Approximately 84,795 individuals nationwide |
| Data exposed | Full name, address, Social Security number, driver license or state ID, passport number, date of birth, financial account details, payment card data, and in some cases medical or health insurance information |
| Assistance line | 1 877 782 4279 (Monday to Friday, 9 am to 9 pm Eastern) |
| Free offer to victims | Complimentary credit monitoring enrollment |
What Actually Happened Inside Eisner Advisory Group
Eisner Advisory Group is not a small local shop. It operates under the much larger EisnerAmper umbrella, a professional services firm with thousands of employees and hundreds of millions in yearly revenue, offering audit, tax, and business advisory work to a huge client base across the country.
That scale is exactly why this event matters so much. When a firm this large stores names, Social Security numbers, medical records, and financial account details for tens of thousands of clients, a break in its defenses does not stay small.
According to the company's own account and multiple state attorney general filings, someone outside the organization managed to slip into internal systems for a short window between September 4 and September 9 of 2023. The company noticed something was off almost immediately and shut the intrusion down. That part sounds reassuring. What comes next is the part people find frustrating.
Why Did It Take So Long to Tell People
Here is where the timeline gets uncomfortable for anyone affected. The intrusion happened in September 2023, yet the notification letters were not mailed until April 8, 2025. That is a gap of roughly a year and a half. Regulators and class action attorneys have asked the same question everyone reading this is probably asking right now. Why so long?
The honest answer, based on the firm's own review completed on February 13, 2025, comes down to the messy nature of stolen files. When attackers pull data out of a network, they rarely grab a neat spreadsheet with clear labels. Instead they often walk away with a jumble of documents, scanned forms, email attachments, and free form files that have no consistent structure.
Investigators then have to manually or semi automatically sift through every single file to identify which specific person's name, number, or record appears where. For a firm handling client data across accounting, tax, and advisory services, that process took months of dedicated forensic work before Eisner could even say with confidence who was impacted and what exactly was exposed.
It is a slow and tedious process, but it is also the reason the eventual notice was accurate rather than a rushed guess.
The Data That Was Exposed
Not every data breach is equally dangerous. Some only expose an email address, which is annoying but rarely life altering. This one is different because of the depth of information involved. Based on notifications filed with multiple state regulators, the categories of exposed data include the following.
- Full legal name and home address
- Social Security number
- Driver license number or other state issued identification number
- Passport number
- Date of birth
- Financial account information
- Payment card numbers
- Medical information and health insurance details for a portion of affected individuals
Put together, this is close to a complete identity kit. A Social Security number combined with a date of birth and address is often enough on its own to open a fraudulent credit line, file a fake tax return in someone's name, or pass identity checks with a bank. Add a driver license number or passport number and criminals gain the ability to create convincing fake identification.
Add financial account or payment card data and the risk moves from long term identity fraud into immediate account takeover territory. Medical information adds yet another layer, since health records can be used for insurance fraud or targeted scams that reference real diagnoses or treatments to sound convincing.
How to Find Out If You Are One of the 84,795
Eisner Advisory Group reported that approximately 84,795 people across the United States were affected. If your data was involved, the company was required by law to mail you a written notice describing exactly what categories of your personal information were exposed.
If you already received that letter, keep it somewhere safe. It is proof of the incident and may matter later if you decide to pursue any compensation or need to prove identity theft resulted directly from this event.
If you worked with Eisner Advisory Group or EisnerAmper in any capacity, whether through tax preparation, audit work, or business advisory services, and you have not received a letter but are unsure, you can call the dedicated assistance line at 1 877 782 4279, available Monday through Friday from 9 am to 9 pm Eastern time. You can also reach the firm by mail at Attn Partner in Charge, 2501 S Wayzata Blvd, Minneapolis, MN 55405.
Your Immediate Action Plan, Step by Step
Whether you have already received a letter or you simply want to be careful, here is the order of operations that actually protects you, explained in plain language rather than legal jargon.
Step 1: Understand the Difference Between a Fraud Alert and a Credit Freeze
A fraud alert is a lightweight tool. It tells lenders to take extra verification steps before opening new credit in your name. A standard fraud alert lasts one year, though confirmed identity theft victims can request an extended alert that lasts seven years. It is easy to set up and free.
A credit freeze is the stronger option. Once active, it locks your credit file so tightly that no lender can even view it to approve new credit, which means a thief cannot open a new account in your name even if they have your Social Security number in hand. You can freeze and unfreeze it yourself whenever you actually need to apply for credit.
For a breach this serious, involving SSNs, dates of birth, and government ID numbers, a full credit freeze is the safer route rather than relying on an alert alone.
Step 2: Contact All Three Credit Bureaus
You need to freeze your file with all three bureaus separately, since each one keeps an independent record.
| Bureau | Phone | Mailing Address |
|---|---|---|
| Equifax | 1 888 298 0045 | P.O. Box 105788, Atlanta, GA 30348 |
| Experian | 1 888 397 3742 | P.O. Box 9554, Allen, TX 75013 |
| TransUnion | 1 833 395 6938 | P.O. Box 160, Woodlyn, PA 19094 |
Step 3: Gather Your Documents Before You Call
To place a freeze or dispute fraudulent activity, bureaus typically ask for the following, so have them ready.
- Full legal name, including any suffix such as Jr, Sr, or III
- Social Security number and date of birth
- Two to five years of address history
- A current proof of address such as a utility or phone bill
- A copy of a government issued photo ID
- A police report or identity theft complaint copy, if you already filed one
Step 4: Pull Your Free Credit Reports and Watch Them Closely
Every consumer is entitled to a free credit report from each bureau through annualcreditreport.com or by calling 1 877 322 8228. After a breach of this size, do not treat this as a once a year chore.
Pull your reports now, then check back regularly over the following months and watch for accounts, inquiries, or addresses that you do not recognize.
Know Your Rights Depending on Where You Live
Data breach laws are not identical in every state, and a few states give extra protections worth knowing about.
- Massachusetts residents have a specific legal right to obtain a copy of any related police report.
- Residents of the District of Columbia can contact the Attorney General's office at oag@dc.gov or 1 202 727 3400.
- Maryland residents can reach their AG office at 1 888 743 0023.
- New Mexico residents have rights under the Fair Credit Reporting Act, including the right to know their credit score, the right to correct inaccurate information, and the right to pursue legal damages in certain cases.
- New York residents can contact the Attorney General at 1 800 771 7755.
- North Carolina residents can reach the AG office at 1 877 566 7226.
- Rhode Island reported 53 affected residents and those individuals retain specific legal protections along with the right to obtain a police report.
If You Suspect Identity Theft, Escalate to the Federal Trade Commission
If you notice suspicious activity tied to your identity after this breach, the Federal Trade Commission is the right place to file an official complaint and generate a personalized recovery plan.
- Portal: identitytheft.gov
- Phone: 1 877 438 4338, TTY 1 866 653 4261
- Mail: Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, DC 20580
Filing through identitytheft.gov gives you an official recovery plan and a report you can use with creditors, banks, and credit bureaus if you need to prove that fraudulent activity traces back to identity theft rather than your own error.
Official Reference for This Incident
You can review the original consumer notice that Eisner Advisory Group filed with a state regulator directly through the Vermont Attorney General's official breach notice filing, which is a public government record confirming the incident, the timeline, and the categories of exposed data described in this article.
Frequently Asked Questions
Why did Eisner Advisory Group take over a year to notify affected people?
The delay came from the forensic review process. Stolen files were not neatly organized, so investigators had to manually sort through unstructured documents to confirm exactly whose data appeared and in what form. That review finished on February 13, 2025, and letters followed on April 8, 2025.
Will freezing my credit affect my current credit cards or loans?
No. A credit freeze only blocks new credit applications and inquiries. Any account you already hold continues working exactly as before. You only need to temporarily lift the freeze if you plan to apply for new credit.
Is Eisner Advisory Group offering free credit monitoring?
Yes. Affected individuals are being offered complimentary credit monitoring enrollment as part of the company's response to the breach.
How do I know a notice claiming to be from Eisner is real and not a phishing attempt?
Verify it against the official assistance line, 1 877 782 4279, and the official mailing address at 2501 S Wayzata Blvd, Minneapolis, MN 55405. Never click links or call numbers printed in unsolicited emails or texts claiming to be from Eisner. Go directly to the verified contact details instead.
What information specifically was exposed in the Eisner Advisory Group data breach?
Names, addresses, Social Security numbers, driver license or state ID numbers, passport numbers, dates of birth, financial account information, payment card numbers, and for some individuals, medical information and health insurance details.
Wrap Up
A breach involving Social Security numbers, government ID numbers, and financial data is not something to shrug off. The good news is that the response does not need to be complicated. Freeze your credit with all three bureaus, pull your free reports and actually read them, keep the official notification letter somewhere safe, and stay alert for any communication pretending to be from Eisner that asks for information over the phone or by email.
Identity thieves are patient and they often wait months before acting on stolen data, so ongoing vigilance matters more than a single one time check. Taking these steps now puts you back in control of your own information.
Related Reading From Hoplon Infosec
If you want to understand how this fits into the wider pattern of professional services firms getting hit by data breaches, these related breakdowns from Hoplon Infosec are worth a look.
- EY data breach exposing client tax data, another major accounting firm incident that mirrors many of the same risks seen in the Eisner case
- LexisNexis data breach, covering how a major data broker's exposure put identity verification records at risk
- DoorDash data breach, an example of how even contact information alone can fuel phishing campaigns
- Oracle Gen 1 server data breach, a deeper look at how legacy systems become an easy entry point for attackers
- SK Telecom cyber attack, showing how a breach at massive scale plays out for millions of subscribers




-20260731111414.webp&w=3840&q=75)
