HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
TERREPOWER, LLC
bd_3d038187d2c14c4c · schema v1 · pii pii-v1
Full breach record for TERREPOWER, LLC →TERREPOWER, LLC notified the Maryland AG of an unauthorized network access between Dec 12-16, 2024, detected on Dec 15, 2024. The incident involved the potential copying of files containing names and Social Security numbers. One Maryland resident was notified. TERREPOWER engaged law enforcement, offered 12 months of Experian credit monitoring, and implemented additional employee safeguards.
Maryland clock⏱ MD AG >30d12 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_649e0458ff4e42c8Indiana State AGfiled 2025-03-07Verified
- bd_f31aa13d94b6fc5cNew Hampshire State AGfiled 2025-03-07Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376518.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 7, 2025
- Raw hash
- 86759bdd48ccdafa07682b9369464a678c32303542b07a9f3539dd6bf22857b5
Reporting entity
- Name
- TERREPOWER, LLCnorm: terrepower
Victim entity
- Name
- TERREPOWER, LLCnorm: terrepower
Incident
- Discovered
- Dec 15, 2024
- Materiality determined
- —
- Notification sent
- Mar 7, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcementProvided written notice to relevant state regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(82 days from discovery to filing)
- Compliance flags
- MD AG >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.