HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Amerman, Ginder & Co.
bd_4b91f5db0f366f53 · schema v1 · pii pii-v1
Full breach record for Amerman, Ginder & Co. →Amerman Ginder & Co, LLC reported a data security incident to the Maryland Attorney General on March 5, 2025. The breach involved unauthorized access to personal information, including names and Social Security numbers, of 9 Maryland residents. The incident was discovered on September 28, 2024, when unusual network activity was detected. Amerman engaged cybersecurity experts, secured systems, and notified the FBI. Affected individuals were offered 12 months of credit monitoring and identity theft restoration services through Kroll.
Maryland clock✗ MD AG >90d23 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5eaccec51aa9cf5eIndiana State AGfiled 2025-03-05Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376511.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 5, 2025
- Raw hash
- 0393337f00ba2ee66709d8127e3877cb46c403540011364f472cd8c3251a1c49
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Amerman, Ginder & Co.norm: amerman ginder
Incident
- Discovered
- Sep 28, 2024
- Materiality determined
- —
- Notification sent
- Mar 5, 2025
- Affected individuals
- 9
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 weeks(158 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.