Social EngineeringPhishingCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Ciuni & Panichi, Inc.
bd_8e5ec1466977181d · schema v1 · pii pii-v1
Full breach record for Ciuni & Panichi, Inc. →Ciuni & Panichi, Inc., an accounting firm, notified the Maryland Attorney General of a data security incident involving unauthorized access to an employee email account. The breach potentially exposed the names, dates of birth, and Social Security Numbers of 495 Maryland residents who were clients of the firm. The incident was discovered on November 3, 2024, and notifications were sent starting February 14, 2025. The firm engaged forensic specialists, changed passwords, and offered credit monitoring services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed495 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376822.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- 9aa921a90225571885134ceb9eeb3ad79d9f9a4169a659f2f35f8c3efa60ced8
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- Ciuni & Panichi, Inc.norm: ciuni panichi
Incident
- Discovered
- Nov 3, 2024
- Materiality determined
- —
- Notification sent
- Feb 14, 2025
- Affected individuals
- 495
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 18 months(536 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.