HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
HMC Partner
bd_356d532e0f2c9729 · schema v1 · pii pii-v1
Full breach record for HMC Partner →HMC Partners notified the Maryland AG of an email account compromise on August 13, 2024. An unknown actor accessed an employee's account, exposing one Maryland resident's name, SSN, and financial account info. HMC secured the account, notified law enforcement, and provided 12 months of Experian IdentityWorks. Notification was sent January 21, 2025.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376219.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 3ebaaacbb2301419999ef60ee9c9f909137c0eee9de30fb54ef7bb5c1c7a23cc
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- HMC Partnernorm: hmc partner
- Domain
- hmcpartner.com
Incident
- Discovered
- Aug 13, 2024
- Materiality determined
- —
- Notification sent
- Jan 21, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 months(457 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.