HackingFinancial ServicesFinanceCustomer Data InvolvedData ExfiltratedDelayed DiscoveryPIIPHIPCIIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICFINANCIAL_CREDENTIALSMediumContained
ScrogginsGrear, Inc.
bd_86ba4d91bc3ec0ae · schema v1 · pii pii-v1
Full breach record for ScrogginsGrear, Inc. →ScrogginsGrear, Inc. (financial/tax services, Cincinnati OH) suffered unauthorized access to a single employee email account by an unknown external actor. Breach date: Aug 25, 2025; discovered Sep 10, 2025. Exposed data: name, DOB, driver's license, bank account numbers, health insurance policy, patient account numbers, SSN/ITIN. 4 of 8,919 total affected individuals were Maine residents. Notifications sent Apr 7, 2026.
Maine clockDiscovered Sep 10, 2025 → Filed with AG Apr 15, 2026217d ✗ ME AG >90d31 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_a557065d807aa681Indiana State AGfiled 2026-04-07(8d gap)Candidate
- bd_c26fdefc73f53d55Indiana State AGfiled 2026-04-07(8d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/667bb5e7-b7f6-4a93-b09d-ad81bd5d6b5b.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 15, 2026
- Raw hash
- aea125355501b6b51035f84833615d248c71470ab18ccd75b791b086256fd34a
Reporting entity
- Name
- ScrogginsGrear, Inc.norm: scrogginsgrear
- Domain
- scrogginsgrear.com
- Industry
- Financial Services
Victim entity
- Name
- ScrogginsGrear, Inc.norm: scrogginsgrear
- Domain
- scrogginsgrear.com
- Industry
- Financial Services
- Industry
- Financial Servicesllm
Incident
- Discovered
- Sep 10, 2025
- Materiality determined
- —
- Notification sent
- Apr 7, 2026
- Affected individuals
- 4
- Data types
- PIIPHIPCIIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 31 weeks(217 days from discovery to filing)
- Compliance flags
- ME AG >90d · 217dME resident >180d · 209d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Sep 10, 2025→ Filed with AG: Apr 15, 2026217d 90 days ME AG >90d Maine Discovered: Sep 10, 2025→ Notified: Apr 7, 2026209d 180 days ME resident >180d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.