Social EngineeringProfessional ServicesProfessional ServicesVishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryData ExfiltratedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
FOLEY & LARDNER LLP
bd_898cb8813948a3a4 · schema v1 · pii pii-v1
Full breach record for FOLEY & LARDNER LLP →Foley & Lardner LLP, a law firm based in Milwaukee, WI, reported a vishing incident involving a single firm-associated individual. Unauthorized access to a limited set of files occurred between April 17–22, 2025, discovered on April 28, 2025. A comprehensive data review concluded December 18, 2025, confirming name and Social Security numbers were potentially exposed. Eight Maine residents were affected. IDX identity protection services were offered for 12 months.
Maine clockDiscovered Apr 28, 2025 → Filed with AG Dec 23, 2025239d ✗ ME AG >90d34 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_4da4609aaf3c345cVermont State AGfiled 2025-12-23Verified
- bd_89b9db805c170f69Indiana State AGfiled 2025-12-23Verified
- bd_d60314d578e1be2eNew Hampshire State AGfiled 2025-12-23Verified
- bd_cf1750c27662f9d5Texas State AGfiled 2025-12-29(6d gap)Verified by operator
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/462c2913-d100-4ac8-80cf-1352c9fd7880.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2025
- Raw hash
- 723bc6e36399605a3a23d0572066fd073a2b4faf938845100ad8d1f4aa2d9f9b
Reporting entity
- Name
- FOLEY & LARDNER LLPnorm: foley lardner
- Domain
- foley.com
- Industry
- Legal Services
Victim entity
- Name
- FOLEY & LARDNER LLPnorm: foley lardner
- Domain
- foley.com
- Industry
- Legal Services
- Industry
- Professional Servicesllm
Incident
- Discovered
- Apr 28, 2025
- Materiality determined
- Dec 18, 2025
- Notification sent
- Dec 23, 2025
- Affected individuals
- 8
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified FBINotified Maine Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 34 weeks(239 days from discovery to filing)
- Compliance flags
- ME AG >90d · 239dME resident >180d · 239d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Apr 28, 2025→ Filed with AG: Dec 23, 2025239d 90 days ME AG >90d Maine Discovered: Apr 28, 2025→ Notified: Dec 23, 2025239d 180 days ME resident >180d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.