Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Erb & Young Insurance Inc
bd_857bbf60c7c03e8c · schema v1 · pii pii-v1
Full breach record for Erb & Young Insurance Inc →Erb & Young Insurance, Inc. notified the Maryland Attorney General of a security incident involving unauthorized access to employee email accounts between January 7 and January 9, 2025. The breach exposed the names and driver's license numbers of two Maryland residents. Notifications were sent on March 30, 2025, offering one year of credit monitoring and identity theft restoration services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376758.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- 588d98b7f644cda58bbf559f823e41623201579f49f07f5b2dc624fb236c4a80
Reporting entity
- Name
- Jonathan R. Knightnorm: jonathan r knight
Victim entity
- Name
- Erb & Young Insurance Incnorm: erb young insurance
- Industry
- financial_services
Incident
- Discovered
- Jan 9, 2025
- Materiality determined
- —
- Notification sent
- Mar 30, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General's Office
- Initial access
- phishing_link
Compliance
- Time to disclose
- 16 months(469 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.