Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Merchants Bank
bd_01647b4490b4eb37 · schema v1 · pii pii-v1
Full breach record for Merchants Bank →Merchants Bank notified the Maryland Attorney General of a phishing incident on September 11, 2024, affecting one employee's email account. The breach exposed the personal information (name, SSN, financial account numbers) of approximately two Maryland residents. Discovery occurred on February 24, 2025, following forensic review. Notifications and credit monitoring services were offered to affected individuals starting March 25, 2025.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376753.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- ea4cab1dcef98b904fbbfa74299646463f147b28925854b42c5503043417014f
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- Merchants Banknorm: merchants bank
- Industry
- financial_services
Incident
- Discovered
- Feb 24, 2025
- Materiality determined
- —
- Notification sent
- Mar 25, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Maryland Attorney General's Office
- Initial access
- phishing_link
Compliance
- Time to disclose
- 14 months(423 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.