Understanding your Squire & Co. data breach notification letter
If a Squire & Co. letter arrived in your mailbox, here is what it means, why you received it, and the free steps you can take right now.
Why you received this letter
Squire & Co. operates as a prominent professional services firm, specializing in accounting, auditing, tax preparation, and comprehensive financial consulting for individuals, businesses, and corporate entities. Because of the core nature of their operations, Squire & Co. occupies a position of deep trust, routinely handling an extensive volume of highly sensitive, non-public personal and corporate financial information. To perform comprehensive financial audits, prepare complex tax returns, and execute payroll or advisory services, the firm must collect and retain exceptionally private records. This includes detailed income statements, asset valuations, social security numbers, banking details, and historical tax documents, making their digital infrastructure an attractive repository for malicious actors seeking high-value financial data. Following reports of a cyber security incident disclosed to the Idaho Attorney General, concerns have arisen regarding the security posture and network vulnerabilities of Squire & Co. While comprehensive forensic reports continue to emerge, incidents impacting professional services and accounting firms typically involve unauthorized access to internal document-management systems, sophisticated malware deployment, or targeted ransomware attacks. In many instances, threat actors exploit vulnerabilities in remote-access gateways or utilize compromised employee credentials to infiltrate networks where sensitive client files are stored. Once inside, these unauthorized parties can quietly exfiltrate vast quantities of confidential data before detection mechanisms are triggered. A data breach at an accounting and financial advisory firm exposes a dangerous cross-section of personal and financial information. Affected individuals commonly face the unauthorized disclosure of full names, dates of birth, Social Security numbers, banking and direct deposit account numbers, routing numbers, and detailed past tax filings. The compromise of this specific data creates severe, long-term risks for victims. Social Security numbers and dates of birth form the foundational components required to execute identity theft and open fraudulent financial accounts. Furthermore, exposed tax and banking records provide cybercriminals with the precise leverage needed to file fraudulent tax returns, intercept government refunds, or execute targeted phishing schemes and financial account takeovers that can plague victims for years. Entities such as Squire & Co. have a strict legal and ethical obligation to implement and maintain robust administrative, physical, and technical safeguards to protect confidential client data. Under state consumer protection statutes, the Federal Trade Commission Act, and common law standards of care, professional services firms are required to encrypt sensitive files, enforce multi-factor authentication, monitor network traffic, and conduct regular security assessments. The occurrence of a data breach of this magnitude serves as strong prima facie evidence that these required security standards were compromised or ignored. A failure to adequately secure network perimeters and restrict access to highly sensitive financial records directly breaches the implied contract of confidentiality between the firm and its clients. For individuals who have received an official data breach notification letter from Squire & Co., this correspondence serves as formal legal acknowledgment that your private information was compromised due to corporate negligence. Legally, the receipt of this letter establishes the necessary standing to participate in a class action lawsuit aimed at demanding accountability, securing compensation for mitigation efforts, and forcing structural cybersecurity reforms. Crucially, affected class members do not need to prove that actual financial theft or identity fraud has already occurred to seek relief; the increased risk of future harm and the mandatory expenditure of time and money on credit monitoring services are legally actionable. Our firm evaluates these cases on a strict contingency fee basis, meaning you pay absolutely nothing out of pocket, and we only collect a fee if we successfully recover compensation on your behalf.
Information the filing reports as involved
- Full Name
- Social Security Number
- Date of Birth
- Tax Return Information
- Financial Account Number
- Routing Number
- Wage and Compensation Information
- Mailing Address
What to do after the letter
Confirm the notice is genuine
A legitimate Squire & Co. notice references the specific incident reported to the Idaho Attorney General and describes which categories of your information were involved. Compare the letter against the public filing before acting on any links or phone numbers it contains.
Keep the letter — it is your proof of connection
The notification letter is the document that ties your personal information to this incident. Keep the original and photograph it. If you later request a case review, this letter is the strongest evidence that you were among the affected individuals.
Protect your accounts and credit
Depending on what was exposed, consider a free credit freeze with all three bureaus, new passwords for reused credentials, and monitoring of financial statements. These steps are free and do not require you to wait for anyone's permission.
Check the record against the public filing
You can verify the Squire & Co. incident against the filing reported to the Idaho Attorney General. This registry summarizes what was filed; it does not provide legal advice.
This page summarizes a data breach reported to the Idaho Attorney General for informational purposes. DataBreachCaseFile.com is a neutral reference registry and does not provide legal advice.