HackingCustomer Data InvolvedIDENTITY_BASICLowContained
McLaughlin & Stern LLP
bd_4248a16a41f158e7 · schema v1 · pii pii-v1
Full breach record for McLaughlin & Stern LLP →McLaughlin & Stern, LLP notified consumers on July 3, 2025, that on April 7, 2025, an unknown actor copied or downloaded certain data. The firm engaged third-party specialists to investigate and confirmed network security. The breach involved names and other data elements. The firm implemented additional safeguards and offered complimentary credit monitoring and identity protection services. Rhode Island residents were specifically noted as impacted.
Vermont clock✗ VT AG >45 bday12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by silentransomgroup about this victim predates this filing by 88 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_a13ed0fa91e417d6Leak Sitesilentransomgroupfiled 2025-04-05(89d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_2f536740152c6beaMaine State AGfiled 2025-07-03Verified
- bd_cfaaaf758e7fdb2bNew Hampshire State AGfiled 2025-07-03Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-03-mclaughlin-stern-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 3, 2025
- Raw hash
- ffe720feb5a6a3013ee6ebe148e434f7673210d140ed829cdd0342ce205437c6
Reporting entity
- Name
- McLaughlin & Stern LLPnorm: mclaughlin stern
- Domain
- mclaughlinstern.com
Victim entity
- Name
- McLaughlin & Stern LLPnorm: mclaughlin stern
- Domain
- mclaughlinstern.com
Incident
- Discovered
- Apr 7, 2025
- Materiality determined
- —
- Notification sent
- Jul 3, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
Compliance
- Time to disclose
- 12 weeks(87 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.