HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
The Longleaf Alliance
bd_508fabb9c1d24d37 · schema v1 · pii pii-v1
Full breach record for The Longleaf Alliance →The Longleaf Network, LLC reported a cybersecurity incident to the Maryland Attorney General on March 3, 2025. Between May 19 and May 29, 2024, an unauthorized actor accessed the company's network, potentially exposing the name and health insurance information of one Maryland resident. The company contained the incident, investigated the scope, and provided one year of complimentary credit monitoring through Experian to the affected individual. No evidence of misuse was found.
Maryland clock✗ MD AG >90d40 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_162b40d20a1b4e52Vermont State AGfiled 2025-03-03Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376474.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 3, 2025
- Raw hash
- 8c07e7b06f7260a56ef4b50cead3c834bea4e4ce2990455f8b047fbcdabc5ca5
Reporting entity
- Name
- The Longleaf Alliancenorm: the longleaf alliance
- Domain
- longleafalliance.org
Victim entity
- Name
- The Longleaf Alliancenorm: the longleaf alliance
- Domain
- longleafalliance.org
Incident
- Discovered
- May 29, 2024
- Materiality determined
- —
- Notification sent
- Mar 3, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- notified requisite state regulatory authorities and law enforcement of this incident
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 40 weeks(278 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.