Social EngineeringPhishingCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Caiafa & Company, LLC
bd_4a15a51cd4f0cbd5 · schema v1 · pii pii-v1
Full breach record for Caiafa & Company, LLC →Caiafa & Company, LLC reported a security incident to the Maryland Attorney General involving unauthorized access to an employee's email account on or around August 27, 2024. The breach exposed one Maryland resident's name, Social Security number, and financial account number. Notification was sent on January 28, 2025, offering one year of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376256.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- bcea7dcb1911637fceb180bb462920e7201bcc6976bb71eca8da553756786b8f
Reporting entity
- Name
- Caiafa & Company, LLCnorm: caiafa
- Domain
- caiafacompany.com
Victim entity
- Name
- Caiafa & Company, LLCnorm: caiafa
- Domain
- caiafacompany.com
Incident
- Discovered
- Aug 27, 2024
- Materiality determined
- —
- Notification sent
- Jan 28, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 15 months(443 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.