HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
HCF of Edinboro Inc.
bd_2d3589ca9b4c18b4 · schema v1 · pii pii-v1
Full breach record for HCF of Edinboro Inc. →HCF of Edinboro Inc. (Edinboro Manor) reported a data breach affecting 2 Maryland residents. Unauthorized access occurred on September 17, 2024, via the management company's computer systems. Personal information exposed included names, DOB, SSN, financial account numbers, and medical/insurance data. Notifications were mailed on January 9, 2025, offering credit monitoring. The incident is contained.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376175.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 420500d37794fd4e2c545c70a3773c284bf4a77b3e10b970d5ab18344fc48648
Reporting entity
- Name
- Polsinelli PCnorm: polsinelli
Victim entity
- Name
- HCF of Edinboro Inc.norm: hcf of edinboro
Incident
- Discovered
- Oct 3, 2024
- Materiality determined
- —
- Notification sent
- Jan 9, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Maryland Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 months(406 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.