Mercer Advisors Inc.
bd_74d6e3e7644e603d · schema v1 · pii pii-v1
Full breach record for Mercer Advisors Inc. →2 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Shinyhunters on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Updated: 21 Feb 2026
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Feb 21, 2026
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- Massachusetts State AGbd_0a5f73a7f4b8af802026-03-31 · +38dVerified by operator
- Nebraska State AGbd_17b4a213c92589c22026-03-31 · +38dVerified
- California State AGbd_41c52380b4cba0f82026-03-31 · +38dVerified by operator
- Vermont State AGbd_7a9028119074fbf32026-03-31 · +38dVerified by operator
Show 5 more filings ↓Show fewer ↑up to 55d gap
- Washington State AGbd_c9cf67fb541b27502026-03-31 · +38dVerified
- Indiana State AGbd_cf90fb475588f3162026-03-31 · +38dVerified
- Montana State AGbd_f0e3ca9ef62041f12026-03-31 · +38dVerified
- Texas State AGbd_7434b0177f07c09a2026-04-02 · +40dVerified
- Oregon State AGbd_4c2c111384c827792026-04-17 · +55dVerified
Filing propagation · 10 filings · 9 states
View merged incident ↗Pattern: first filing Feb 21, last Apr 17 (OR) — a 55-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
shinyhunters
According to ransomware.live, ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.