HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
KMB Design Group
bd_599e7b3458b8e6a1 · schema v1 · pii pii-v1
Full breach record for KMB Design Group →KMB Design Group LLC notified the Maryland Attorney General of a cybersecurity incident affecting 7 Maryland residents. Unauthorized access occurred on or about March 19, 2024. The breach involved the exfiltration of personal information including names, DOBs, SSNs, driver's license numbers, financial account info, and health/medical data. KMB engaged forensic experts, contained the incident, and is offering complimentary credit monitoring via Experian IdentityWorks to affected individuals. Notifications were sent on January 28, 2025.
Leak gap clock✗ Leak >180d20 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7 affectedView incident
A leak claim by black_basta about this victim predates this filing by 604 days.View originating leak claim
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376253.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 16c28a8abe898c2d45efa2eb77957ace1f638da96abc9e3e931040c95ddeefbc
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- KMB Design Groupnorm: kmb design
- Domain
- kmbdg.com
Incident
- Discovered
- Mar 19, 2024
- Materiality determined
- —
- Notification sent
- Jan 28, 2025
- Affected individuals
- 7
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 months(604 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.