HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Valsoft Corporation Inc.
bd_33dcd03d26cdcefe · schema v1 · pii pii-v1
Full breach record for Valsoft Corporation Inc. →Valsoft Corporation Inc. d/b/a AllTrust notified the Maryland Attorney General of a data event affecting 668 Maryland residents. An unauthorized actor accessed the network of subsidiary Aspire USA, LLC between Feb 12-15, 2024, taking files containing names, SSNs, driver's licenses, and financial data. AllTrust engaged forensic specialists, secured the network, and provided 12 months of credit monitoring to affected individuals.
Maryland clock✗ MD AG >90d13 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_4859b1729dbacf98Oregon State AGfiled 2025-02-27Verified
- bd_b79c2aca9da1c1e7New Hampshire State AGfiled 2025-02-27Verified
- bd_bb927d09f25ad525Indiana State AGfiled 2025-02-27Verified
- bd_daba09a034e6a806Washington State AGfiled 2025-02-27Verified
Show 3 more filings ↓Show fewer ↑up to 68d gap
- bd_e78901becd64e305Maine State AGfiled 2025-02-27Verified
- bd_f4848f23e5b232f9Montana State AGfiled 2025-02-27Verified
- bd_6f5bf1a82e506b15New Hampshire State AGfiled 2025-05-06(68d gap)Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376430.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2025
- Raw hash
- cc920f1da0f562f4f043dc15f83ae16556a9b55fc8de3f5960fc24dccfc15f2f
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Valsoft Corporation Inc.norm: valsoft
Incident
- Discovered
- Feb 14, 2024
- Materiality determined
- Feb 27, 2025
- Notification sent
- Feb 27, 2025
- Affected individuals
- 668
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified Maryland Attorney GeneralNotified Equifax, Experian, and TransUnion
- Third party
- via Aspire USA, LLC
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 months(379 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.