Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
St. Andrew's Resources for Seniors System
bd_6d5d589606fe7c79 · schema v1 · pii pii-v1
Full breach record for St. Andrew's Resources for Seniors System →St. Andrew’s Resources for Seniors System notified the Maryland AG of a phishing incident affecting 31 Maryland residents. Unauthorized actors accessed employee email accounts, exposing names, SSNs, driver’s licenses, financial/medical info. Notification sent Feb 7, 2025. Credit monitoring offered.
Maryland clock✗ MD AG >90d12 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0d1f90635147cec4Montana State AGfiled 2025-02-07Candidate
- bd_6e405b804d6ffeb3HHS OCRfiled 2025-02-07Verified
- bd_70d01264a0919451Indiana State AGfiled 2025-02-07Verified
- bd_732dd450e270af9bOregon State AGfiled 2025-02-07Verified
Show 1 more filing ↓Show fewer ↑
- bd_fbcfd72a1ec6a335Maine State AGfiled 2025-02-07Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376335.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 7, 2025
- Raw hash
- b3cb4f63b4297c215cd73c8ee98b5bd26375950b7b96bb3929ab04d14937b6fa
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- St. Andrew's Resources for Seniors Systemnorm: st andrew s resources for seniors system
- Domain
- standrews1.com
Incident
- Discovered
- Feb 8, 2024
- Materiality determined
- —
- Notification sent
- Feb 7, 2025
- Affected individuals
- 31
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney GeneralProvided notice to the three major credit reporting agencies
- Initial access
- phishing_link
Compliance
- Time to disclose
- 12 months(365 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.