HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIHighContained
Wolf Haldenstein Adler Freeman & Herz LLP
bd_747af5a683f6a74f · schema v1 · pii pii-v1
Full breach record for Wolf Haldenstein Adler Freeman & Herz LLP →Wolf Haldenstein Adler Freeman & Herz LLP reported a cybersecurity incident to the Maryland Attorney General on January 14, 2025. The firm detected suspicious activity on December 13, 2023, leading to the discovery that an unauthorized actor accessed files containing names, SSNs, employee IDs, and medical diagnoses/claims. Approximately 79,732 Maryland residents were affected. The firm engaged a cybersecurity firm, secured its network, enhanced privacy policies, and offered credit monitoring.
Leak gap clock✗ Leak >180d23 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
A leak claim by black_basta about this victim predates this filing by 691 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_96d242fcec7fed34Maryland State AGfiled 2025-11-13Candidate
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376188.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 25926854766551375f2276562eb00ea905b47f510b2293ecbff08609e0dfcf48
Reporting entity
- Name
- Wilson, Elser, Moskowitz, Edelman & Dicker LLPnorm: wilson elser moskowitz edelman dicker
Victim entity
- Name
- Wolf Haldenstein Adler Freeman & Herz LLPnorm: wolf haldenstein adler freeman herz
- Domain
- whafh.com
Incident
- Discovered
- Dec 13, 2023
- Materiality determined
- —
- Notification sent
- Jan 13, 2025
- Affected individuals
- 79,732
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Filed Security Breach Notification with Maryland Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 months(701 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.