Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
BCM ONE, INC.
bd_0d9c233842394527 · schema v1 · pii pii-v1
Full breach record for BCM ONE, INC. →BCM One, Inc. notified the Maryland Attorney General of a cybersecurity incident involving unauthorized access to an employee email account. The unauthorized access occurred between May 28, 2024, and July 11, 2024. The breach affected five Maryland residents, whose names and financial account or payment card information were accessed via a phishing attack. Notifications were mailed on January 2, 2025.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed5 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376113.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 58d79f496d12c43392375e8a0e76eb6eb3b1a88fceb6b3c90e9f6882a267c700
Reporting entity
- Name
- Patrick Haggertynorm: patrick haggerty
- Domain
- patrickhaggerty.com
Victim entity
- Name
- BCM ONE, INC.norm: bcm one
- Domain
- bcmone.com
Incident
- Discovered
- Dec 4, 2024
- Materiality determined
- —
- Notification sent
- Jan 2, 2025
- Affected individuals
- 5
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 49 weeks(344 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.