HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICPIILowContained
May, Potenza, Baran & Gillespie, P.C.
bd_6905b7cf61eeb0d2 · schema v1 · pii pii-v1
Full breach record for May, Potenza, Baran & Gillespie, P.C. →May, Potenza, Baran & Gillespie, P.C. (MPBG), a Phoenix-based law firm, disclosed a network compromise identified on October 16, 2024. Unauthorized activity impacted files related to legal matters, potentially exposing clients' names and other personal information. MPBG secured the network, engaged third-party forensic experts, collaborated with law enforcement, and offered complimentary credit monitoring and identity restoration services to affected individuals.
Maryland clock✗ MD AG >90d16 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_d1d743b2297035b3Maine State AGfiled 2025-02-04Candidate
- bd_836f398d43174440Indiana State AGfiled 2025-01-31(4d gap)Verified
- bd_09d3ddea3ffe835dNew Hampshire State AGfiled 2025-02-10(6d gap)Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376321.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 4, 2025
- Raw hash
- c6e836964e411c89fa103bba3ca151fc0f21001c4eaf36083f08e581cfb6f472
Reporting entity
- Name
- May, Potenza, Baran & Gillespie, P.C.norm: may potenza baran gillespie
- Industry
- professional_services
Victim entity
- Name
- May, Potenza, Baran & Gillespie, P.C.norm: may potenza baran gillespie
- Industry
- professional_services
Incident
- Discovered
- Oct 16, 2024
- Materiality determined
- —
- Notification sent
- Jan 31, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Collaborated with law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 weeks(111 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.