Social EngineeringFinancial ServicesFinancePhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedDelayed DiscoveryPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICAUTHENTICATIONMediumContained
Upstream Advisory Group LLC
bd_1e586aadde8286ea · schema v1 · pii pii-v1
Full breach record for Upstream Advisory Group LLC →Upstream Advisory Group LLC, a financial services firm in Garner, NC, experienced an email phishing incident in which an unauthorized individual accessed one company email account between May 21 and May 28, 2025. The breach was discovered on August 19, 2025. The account contained names, Social Security numbers, and/or health insurance information of 2 Maine residents. Notifications were mailed September 18, 2025, and one year of credit monitoring via Epiq was offered.
Maine clockDiscovered Aug 19, 2025 → Filed with AG Sep 18, 202530d ✓ ME AG ≤30d4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b813ceb731076d2bIndiana State AGfiled 2025-09-18Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/606368f6-ac1b-45a7-bd7f-bb790a4f7021.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 18, 2025
- Raw hash
- 60cc98b64521f9fa5a00c0b0854ce07056b2012295a25866c293839b7769b0a7
Reporting entity
- Name
- Upstream Advisory Group LLCnorm: upstream advisory
- Industry
- Financial Services
Victim entity
- Name
- Upstream Advisory Group LLCnorm: upstream advisory
- Industry
- Financial Services
- Industry
- Financial Servicesllm
Incident
- Discovered
- Aug 19, 2025
- Materiality determined
- —
- Notification sent
- Sep 18, 2025
- Affected individuals
- 2
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICAUTHENTICATION
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Aug 19, 2025→ Filed with AG: Sep 18, 202530d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.