McElroy, Deutsch, Mulvaney & Carpenter LLP
bd_6da1ae289ac34596 · schema v1 · pii pii-v2
Full breach record for McElroy, Deutsch, Mulvaney & Carpenter LLP →McElroy, Deutsch, Mulvaney & Carpenter LLP (MDMC) reported a cyberattack to Nebraska regulators. Unauthorized access to MDMC systems occurred between March 28 and April 1, 2025. MDMC discovered suspicious activity on April 3, 2025, and confirmed on December 4, 2025, that personal information (names and Social Security numbers) of approximately three Nebraska residents was accessed. MDMC notified federal law enforcement, provided 12 months of credit monitoring via Epiq, and began notifying affected individuals on December 19, 2025. The investigation is ongoing.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 28, 2025
Begins
Apr 3, 2025
Discovered
Dec 19, 2025
Filed
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Indiana State AGbd_698f1a0d029620162025-12-19Verified
- New Hampshire State AGbd_bd3f74df05a359e32025-12-19Verified
- Maine State AGbd_efd18d3b3c3e05362025-12-19Candidate
- New Hampshire State AGbd_03b000a29a602b0c2026-03-12 · +83dCandidate
Show 1 more filing ↓Show fewer ↑up to 83d gap
- Maine State AGbd_df428c93170c98cf2026-03-12 · +83dVerified
Filing propagation · 6 filings · 4 states
View merged incident ↗Pattern: first filing Dec 19 (IN), last Mar 12 (ME) — a 83-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.