Rhodes, Young, Black, and Duncan
bd_09615de228572e2f · schema v1 · pii pii-v1
Full breach record for Rhodes, Young, Black, and Duncan →2 incidents on fileRhodes, Young, Black, and Duncan (RYBD), a tax and accounting firm, notified Nebraska residents of a cybersecurity incident. Unauthorized access occurred on September 17, 2025, via a vulnerability in a SonicWall Firewall (supply chain compromise). Data was exfiltrated before detection on October 12, 2025. RYBD secured the network, engaged outside counsel and cybersecurity experts, and began notifying affected individuals around May 27, 2026. Compromised data likely includes personal information (PII). RYBD offers credit monitoring and identity theft recovery services.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 17, 2025
Begins
Oct 12, 2025
Discovered
Jun 26, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Indiana State AGbd_393ca5d3b08226e82026-06-26Verified
- Massachusetts State AGbd_29db5ca2b0472d4d2026-06-27 · +1dVerified
- New Hampshire State AGbd_b25566f2bd3200e92026-06-29 · +3dCandidate
- Massachusetts State AGbd_db700247ccd17ccf2026-07-14 · +18dVerified
Show 1 more filing ↓Show fewer ↑up to 36d gap
- Massachusetts State AGbd_62dd36e87f691f132026-08-01 · +36dVerified
Filing propagation · 6 filings · 4 states
View merged incident ↗Pattern: first filing Jun 26 (IN), last Aug 1 (MA) — a 36-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.