HackingProfessional ServicesProfessional ServicesData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Heard, McElroy, & Vestal
bd_0fd4bf0b8d3ef8c1 · schema v1 · pii pii-v1
Full breach record for Heard, McElroy, & Vestal →Heard, McElroy, & Vestal LLC (HMV), an accounting firm, identified unusual login activity to its document imaging solution on July 17, 2024. An unauthorized party downloaded client information, which may have included names and Social Security numbers (including tax return data). One Maryland resident was notified on January 6, 2025. HMV notified the FBI and IRS, implemented additional safeguards, and is providing IDX identity protection services.
Maryland clock✗ MD AG >90d22 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376127.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 19, 2026
- Raw hash
- 56e89580754840c2d73b12a32d6661d67b78c030643932d24c50c843639e2f04
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Heard, McElroy, & Vestalnorm: heard mcelroy vestal
- Industry
- Professional Servicesllm
Incident
- Discovered
- Jul 17, 2024
- Materiality determined
- —
- Notification sent
- Jan 6, 2025
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney GeneralNotified the FBINotified the IRS
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 months(671 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.