HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Baltimore Country Club
bd_1cafdd28e2d6c75b · schema v1 · pii pii-v1
Full breach record for Baltimore Country Club →Baltimore Country Club, Inc. notified the Maryland Attorney General of a data security incident discovered on February 1, 2025. Unauthorized access to certain files may have exposed names and Social Security numbers of approximately 267 Maryland residents. The club engaged cybersecurity experts, launched a forensic investigation, and mailed notifications offering 12 months of identity protection services.
Maryland clock⏱ MD AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by play about this victim predates this filing by 34 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_47fd9f96a7c6ae5bLeak Siteplayfiled 2025-01-31(34d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_0a6bc7cef384ae32Montana State AGfiled 2025-08-26(173d gap)Verified
- bd_af8f8d2c96eb8ca4Indiana State AGfiled 2025-08-26(173d gap)Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376514.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 6, 2025
- Raw hash
- fcf5f82899001d43eee12ca8886b0f31222c232be60868168094020ff54cbbed
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Baltimore Country Clubnorm: baltimore country club
- Domain
- bcc1898.com
Incident
- Discovered
- Feb 1, 2025
- Materiality determined
- —
- Notification sent
- Mar 6, 2025
- Affected individuals
- 267
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Maryland Attorney General
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- MD AG >30dLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.