C.E. Niehoff & Company
bd_6a8aff16ee7dbab5 · schema v1 · pii pii-v1
Full breach record for C.E. Niehoff & Company →C.E. Niehoff & Co. reported a ransomware incident affecting 1,509 individuals, including 1 Maine resident. The breach occurred between September 9 and 12, 2021, compromising names and Social Security Numbers. The company notified affected individuals in writing on December 23, 2021, and provided 12 months of credit monitoring through Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 9, 2021
Begins
Sep 12, 2021
Discovered
Dec 23, 2021
Filed
vs. sector median
+6 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- HHS OCRbd_20f054c7e041c61e2021-12-23Verified
- Indiana State AGbd_63922874a05f007c2021-12-23Verified
- Illinois State AGbd_cd66058a9f75ed4f2021-01-01 · +356dCandidate
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Dec 23 (ME) — a 356-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.