Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Independent Financial Advisor (securities offered through Cambridge Investment Research, Inc.)
bd_435f2fd83b7684bf · schema v1 · pii pii-v1
Full breach record for Independent Financial Advisor (securities offered through Cambridge Investment Research, Inc.) →An independent financial advisor (securities offered through Cambridge Investment Research, Inc.) notified the Maryland Attorney General of a data security incident. Unauthorized access to a single email mailbox occurred between September 24 and October 1, 2024, likely via phishing. The incident affected 4 Maryland residents, exposing names, addresses, DOB, SSNs, driver's licenses, and financial account numbers. The advisor engaged forensic reviewers, secured the environment, and offered 12 months of credit monitoring and identity protection services through IDX.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376141.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 062bb21ca3009c9dbfd0b5e607e0969f9b4622dab4733136ebcce689e79fce7f
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Independent Financial Advisor (securities offered through Cambridge Investment Research, Inc.)norm: independent financial advisor securities offered through cambridge investment research
- Industry
- financial_services
Incident
- Discovered
- Oct 1, 2024
- Materiality determined
- —
- Notification sent
- Jan 9, 2025
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 14 months(408 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.