DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDFinancial accountHighContained

Zenith American Solutions

bd_95957ef1c6dd1f31 · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Jan 29, 2025

To disclose

Affected

2,128state residents only

Linked

6 filings

Confidence

67%
Full breach record for Zenith American Solutions5 incidents on file

Zenith American Solutions experienced a security breach on September 3, 2024, via a phishing attack that granted an unauthorized actor access to an employee's email inbox. The incident potentially affected 2,128 Maryland residents, exposing personal data including names, dates of birth, Social Security numbers, and financial/banking information. The company contained the incident, reviewed systems, retrained the affected employee, and instituted additional security safeguards. Affected individuals are being offered free credit monitoring and identity restoration services.

Incident timeline

Sep 3, 2024

Begins

Jan 29, 2025

Filed

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 58d gap

Filing propagation · 6 filings · 6 states

View merged incident ↗
Vermont State AGJan 29 · first
Maryland State AGJan 29 · first · this page

Pattern: first filing Jan 29 (VT), last Mar 28 (NH) — a 58-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.