MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
NewAgeSys Inc
bd_19511b6456ff0865 · schema v1 · pii pii-v1
Full breach record for NewAgeSys Inc →NewAgeSys Inc., a New Jersey-based technology company, notified the Maryland Attorney General of a data security incident. In March 2024, an encryption event disrupted network access, leading to the discovery that an unauthorized actor exfiltrated names and Social Security Numbers. NewAgeSys determined affected data on February 24, 2025, and notified 90 Maryland residents on March 21, 2025. The company implemented additional security protocols and offered credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,087 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376722.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- d08378cd85ff915d5875f2b5f011cb9b8ba88baebc413b0e6b7e7d175304d042
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- NewAgeSys Incnorm: newagesys
Incident
- Discovered
- Feb 24, 2025
- Materiality determined
- —
- Notification sent
- Mar 21, 2025
- Affected individuals
- 90
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General
Compliance
- Time to disclose
- 14 months(423 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.