HackingStolen CredentialsData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumActive
Mendes & Mount LLP
bd_1fd05991781053d9 · schema v1 · pii pii-v1
Full breach record for Mendes & Mount LLP →Mendes & Mount LLP notified the Maryland AG of unauthorized network activity on Feb 1, 2024, affecting one Maryland resident. Compromised data included names, SSNs, and medical info. The firm engaged forensic specialists, notified federal law enforcement, and provided 12 months of credit monitoring. Investigation is ongoing.
Maryland clock✗ MD AG >90d13 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_522e0f97df551417New Hampshire State AGfiled 2025-02-12Verified
- bd_76f848557682d64dMontana State AGfiled 2025-02-12Candidate
- bd_936791d6ec48dffbMaine State AGfiled 2025-02-12Verified by operator
- bd_9e486b2187025f09Indiana State AGfiled 2025-02-12Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376353.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 12, 2025
- Raw hash
- 24782df840b1fa09a224b60447cec04535d8070bab3743c85a3abfec679e1398
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Mendes & Mount LLPnorm: mendes mount
- Domain
- mendes.com
Incident
- Discovered
- Feb 1, 2024
- Materiality determined
- —
- Notification sent
- Feb 12, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified federal law enforcementProviding written notice of this incident to relevant state regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 months(377 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.