HackingFinancial ServicesProfessional ServicesFinanceCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_GOVERNMENTMediumContained
Johnson Vollmerhausen & Gates
bd_70d05c629448572a · schema v1 · pii pii-v1
Full breach record for Johnson Vollmerhausen & Gates →Johnson, Vollmerhausen & Gates, PLLC (JVG), a financial services/legal firm in Asheville, NC, reported an external network breach occurring February 14–22, 2026, discovered March 11, 2026. An unauthorized actor accessed and copied files containing client names and Social Security Numbers. 145 total individuals were affected, including 1 Maine resident. JVG notified the FBI, engaged cybersecurity specialists, and offered 12-month IDX credit monitoring to affected individuals.
Maine clockDiscovered Mar 11, 2026 → Filed with AG Apr 29, 202649d ⏱ ME AG >30d7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by ailock about this victim predates this filing by 52 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_244fd374457a30dcLeak Siteailockfiled 2026-03-07(53d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/e0ca172a-d42a-4710-a56c-8c92610b7b17.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 29, 2026
- Raw hash
- c6027ea7687fad3c165b0d48a3f55467705a266a00ed2b9fb8c26818b9b6b286
Reporting entity
- Name
- Johnson Vollmerhausen & Gatesnorm: johnson vollmerhausen gates
- Domain
- jvgasheville.com
- Industry
- Financial Services
Victim entity
- Name
- Johnson Vollmerhausen & Gatesnorm: johnson vollmerhausen gates
- Domain
- jvgasheville.com
- Industry
- Financial Services
- Industry
- Financial ServicesllmProfessional Servicesllm
Incident
- Discovered
- Mar 11, 2026
- Materiality determined
- —
- Notification sent
- Apr 29, 2026
- Affected individuals
- 1
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Federal Bureau of Investigations notified
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- ME AG >30d · 49dLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 11, 2026→ Filed with AG: Apr 29, 202649d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.