J.M. Forbes & Co.
bd_2d8fdc40759510b0 · schema v1 · pii pii-v1
Full breach record for J.M. Forbes & Co. →J.M. Forbes & Co. detected suspicious activity on its email system on November 17, 2025, which was part of an attempted business email compromise via social engineering. An unauthorized external party accessed an employee email account. The compromised account may have contained personal information including names, addresses, Social Security numbers, and account numbers. The company contained the incident, preventing fraudulent transactions, and is offering two years of credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 17, 2025
Discovered
Apr 7, 2026
Filed
vs. sector median
+1 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- New Hampshire State AGbd_66f15480d78ef9f62026-04-07Verified
- Massachusetts State AGbd_af0270378c3951342026-04-07Verified
- Maine State AGbd_ba4b31877e8d09b12026-04-07Verified by operator
- Nebraska State AGbd_98d54460da9f9c8f2026-07-06 · +90dVerified
Show 1 more filing ↓Show fewer ↑up to 90d gap
- New Hampshire State AGbd_a5dc2e414705c04d2026-07-06 · +90dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Apr 7 (NH), last Jul 6 (NH) — a 90-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.