Social EngineeringFinancial ServicesFinancePhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedEmployee Data InvolvedPIIFINANCIAL_ACCOUNTLowContained
CW Advisors, LLC
bd_08729120ea2d3d26 · schema v1 · pii pii-v1
Full breach record for CW Advisors, LLC →On February 4, 2026, CW Advisors LLC, a financial services firm based in Boston, MA, identified an email phishing incident that resulted in unauthorized access to a limited number of employee email accounts. Investigation completed February 24, 2026, confirmed that one Maine resident's name and financial account number were contained in accessed emails. Notifications were mailed March 26, 2026; one year of credit monitoring offered via Epiq Privacy Solutions.
Maine clockDiscovered Feb 24, 2026 → Filed with AG Mar 26, 202630d ✓ ME AG ≤30d4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6da1bce624130cc3New Hampshire State AGfiled 2026-03-26Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/66bf993a-d5c0-4bb9-91ae-3051a59dc6dc.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 26, 2026
- Raw hash
- 7119345ebe14ec8ae148a09bb64fe5a86cff39a4e05ad4e69f2b8f3e9771d3db
Reporting entity
- Name
- CW Advisors, LLCnorm: cw advisors
- Domain
- cwadvisorsgroup.com
- Industry
- Financial Services
Victim entity
- Name
- CW Advisors, LLCnorm: cw advisors
- Domain
- cwadvisorsgroup.com
- Industry
- Financial Services
- Industry
- Financial Servicesllm
Incident
- Discovered
- Feb 24, 2026
- Materiality determined
- Feb 24, 2026
- Notification sent
- Mar 26, 2026
- Affected individuals
- 1
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 24, 2026→ Filed with AG: Mar 26, 202630d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.