MalwareRansomwareData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICMediumActive
McCoyd, Parkas & Ronan LLP
bd_7eefc74e99acbd31 · schema v1 · pii pii-v1
Full breach record for McCoyd, Parkas & Ronan LLP →McCoyd, Parkas & Ronan LLP, a law firm, disclosed a ransomware attack discovered on May 14, 2026, affecting its network. The breach potentially exposed client PII, including SSNs, DOBs, driver's license numbers, financial account info, and health insurance data. The firm engaged outside counsel, notified the FBI, and is offering 24 months of Experian IdentityWorks. Investigation is ongoing; exact scope of compromised data is unconfirmed. Rhode Island residents were specifically noted as affected.
Massachusetts clock✓ MA AG ≤30d18 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_39460e0cb0dc2731Vermont State AGfiled 2026-06-10(9d gap)Verified
- bd_479589b579b9b8bdNew Hampshire State AGfiled 2026-06-10(9d gap)Verified
- bd_cce5eea352ac1fb0Maine State AGfiled 2026-06-10(9d gap)Candidate
- bd_d2c0c089284c2b91Indiana State AGfiled 2026-06-11(10d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-942-mccoyd-parkas-ronan-llp/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- 2041ce2af8b9dded57b807a0faed7b5a3307e934164a1ccb1e467a4d73cad91d
Reporting entity
- Name
- McCoyd, Parkas & Ronan LLPnorm: mccoyd parkas ronan
Victim entity
- Name
- McCoyd, Parkas & Ronan LLPnorm: mccoyd parkas ronan
Incident
- Discovered
- May 14, 2026
- Materiality determined
- —
- Notification sent
- Jun 11, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notifying state regulators
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- MA AG ≤30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.