HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICPIILowContained
ECKERT SEAMANS CHERIN & MELLOTT, LLC
bd_484695f8cd5e1572 · schema v1 · pii pii-v1
Full breach record for ECKERT SEAMANS CHERIN & MELLOTT, LLC →Eckert Seamans Cherin & Mellott, LLC notified consumers of a cyber incident discovered on April 17, 2025, involving unauthorized access to an attorney's computer and limited firm data, including a 2019 Wheeling Jesuit University alumni list. The firm engaged forensic investigators, notified law enforcement, and contained the incident. No evidence of data release was found. The firm offered one year of Experian identity monitoring services to affected individuals.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_adb0c7d5ca2f239eIndiana State AGfiled 2025-06-18Verified
- bd_b0866f4a8fadf9cdMaine State AGfiled 2025-06-18Candidate
- bd_738e2db0ae358440New Hampshire State AGfiled 2025-06-23(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-06-18-eckert-seamans-cherin-mellott-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 18, 2025
- Raw hash
- 13b030a16a4cc787bf459ed72baa0b9cbdf615c7796ddfdcaf2a18bf2bf5f5f5
Reporting entity
- Name
- ECKERT SEAMANS CHERIN & MELLOTT, LLCnorm: eckert seamans cherin mellott
Victim entity
- Name
- ECKERT SEAMANS CHERIN & MELLOTT, LLCnorm: eckert seamans cherin mellott
Incident
- Discovered
- Apr 17, 2025
- Materiality determined
- —
- Notification sent
- Jun 18, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified all appropriate state regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.