HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
MultistateTax Inc
bd_52521b8d1df0777e · schema v1 · pii pii-v1
Full breach record for MultistateTax Inc →Multistate Tax, Inc. notified the Maryland Attorney General of a data incident involving fraudulent tax filings. Unauthorized actors accessed client data between Jan 31 and Sep 24, 2024, affecting 5 Maryland residents. Data included names, SSNs, and financial account numbers. Multistate Tax engaged third-party specialists, notified the IRS, and provided 12 months of credit monitoring to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_0fe6a60118b97549Leak Siteblackshrantacfiled 2025-11-13Candidate
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376196.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 076560fff7f4876b0b9bc0dc29dee245d7b0879ae5ab00e65c96c8513919f309
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- MultistateTax Incnorm: multistatetax
- Domain
- multistatetax.net
Incident
- Discovered
- Sep 12, 2024
- Materiality determined
- —
- Notification sent
- Jan 15, 2025
- Affected individuals
- 5
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email CollectionT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 months(427 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.