HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIMediumContained
Riley Pope & Laney LLC
bd_09a5c4d47e114ef3 · schema v1 · pii pii-v1
Full breach record for Riley Pope & Laney LLC →Riley Pope & Laney, LLC notified the Maryland AG of unauthorized network access between Aug 11-12, 2024. 46 Maryland residents affected. Data included names, SSNs, driver's licenses, financial accounts, and health info. RPL engaged forensic specialists, notified law enforcement, and offered 12 months of credit monitoring.
Maryland clock✗ MD AG >90d26 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by cicada3301 about this victim predates this filing by 182 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_e9bd630dd78c4f15Leak Sitecicada3301filed 2024-08-14(182d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_535ae6ac4dd71bc7Montana State AGfiled 2025-02-12Candidate
- bd_d3683542a09e86b8Maine State AGfiled 2025-02-12Verified by operator
- bd_e6784912f7512be3Vermont State AGfiled 2025-02-12Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376352.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 12, 2025
- Raw hash
- 3ae2fb585cd1270ed934cfc3527717cbdab2d14f12a89f7904fd7370055e9cad
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Riley Pope & Laney LLCnorm: riley pope laney
- Domain
- rplfirm.com
Incident
- Discovered
- Aug 12, 2024
- Materiality determined
- Feb 12, 2025
- Notification sent
- Feb 12, 2025
- Affected individuals
- 46
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement regarding the eventProviding written notice of this incident to state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 26 weeks(184 days from discovery to filing)
- Compliance flags
- MD AG >90dLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.