Rhodes, Young, Black & Duncan Discloses Major Data Breach Impacting Sensitive Personal and Financial Information
Rhodes, Young, Black & Duncan, a private accounting and advisory firm based in Duluth, Georgia, recently reported a significant data breach involving unauthorized access to one of its backup servers. The firm disclosed the incident to the Massachusetts Office of Consumer Affairs and Business Regulation on August 21, 2026, and began notifying affected individuals around the same time.
The breach was first detected on October 12, 2025, though forensic investigations revealed that intruders initially accessed the firm’s network nearly a month earlier, on September 17, 2025. During this period, unauthorized parties exfiltrated sensitive data before the activity was identified. By May 27, 2026, the firm had notified employers of impacted individuals about the potential exposure of personal information.
The compromised data included a wide range of highly sensitive details:
- Personally identifiable information (PII): Full names, Social Security numbers, taxpayer identification numbers, driver’s license/state ID numbers, and passport numbers.
- Financial data: Bank account and routing numbers, payment card numbers, expiration dates, and current PINs.
- Protected health information (PHI): Health insurance details and medical records.
In response, Rhodes, Young, Black & Duncan is offering affected individuals complimentary identity protection services through IDX, with enrollment instructions provided via notification letters. The firm has also set up a dedicated call center for inquiries and included guidance on placing fraud alerts and security freezes with the three major credit bureaus Equifax, Experian, and TransUnion.
The breach underscores the prolonged exposure of critical financial and personal data, raising concerns about potential identity theft and fraud risks for those impacted.
Source: https://www.claimdepot.com/data-breach/rhodes-young-black-and-2026
Rhodes, Young, Black & Duncan, CPAs cybersecurity rating report: https://www.rankiteo.com/company/rhodes-young-black-&-duncan-cpas
"id": "RHO1787856075",
"linkid": "rhodes-young-black-&-duncan-cpas",
"type": "Breach",
"date": "9/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Accounting/Financial Services',
'location': 'Duluth, Georgia, USA',
'name': 'Rhodes, Young, Black & Duncan',
'type': 'Private accounting and advisory firm'}],
'attack_vector': 'Unauthorized access to backup server',
'customer_advisories': 'Notification letters sent to affected individuals '
'with guidance on identity protection and fraud alerts',
'data_breach': {'data_exfiltration': True,
'personally_identifiable_information': ['Full names',
'Social Security '
'numbers',
'Taxpayer '
'identification '
'numbers',
'Driver’s '
'license/state ID '
'numbers',
'Passport numbers',
'Bank account and '
'routing numbers',
'Payment card numbers',
'Expiration dates',
'Current PINs',
'Health insurance '
'details',
'Medical records'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally identifiable '
'information (PII)',
'Financial data',
'Protected health information '
'(PHI)']},
'date_detected': '2025-10-12',
'date_publicly_disclosed': '2026-08-21',
'description': 'Rhodes, Young, Black & Duncan, a private accounting and '
'advisory firm based in Duluth, Georgia, reported a '
'significant data breach involving unauthorized access to one '
'of its backup servers. The breach exposed sensitive personal '
'and financial information, including PII, financial data, and '
'PHI.',
'impact': {'data_compromised': 'Sensitive personal and financial information, '
'including PII, financial data, and PHI',
'identity_theft_risk': 'High',
'payment_information_risk': 'High',
'systems_affected': 'Backup server'},
'initial_access_broker': {'entry_point': 'Backup server',
'reconnaissance_period': '2025-09-17 to 2025-10-12'},
'investigation_status': 'Completed forensic investigation',
'post_incident_analysis': {'root_causes': 'Unauthorized access to backup '
'server'},
'references': [{'source': 'Massachusetts Office of Consumer Affairs and '
'Business Regulation'}],
'regulatory_compliance': {'regulatory_notifications': ['Massachusetts Office '
'of Consumer Affairs '
'and Business '
'Regulation']},
'response': {'communication_strategy': 'Notification letters, dedicated call '
'center, guidance on fraud alerts and '
'security freezes',
'third_party_assistance': 'IDX (identity protection services)'},
'title': 'Rhodes, Young, Black & Duncan Major Data Breach',
'type': 'Data Breach'}