HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighContained
Wolf Haldenstein Adler Freeman & Herz LLP
bd_96d242fcec7fed34 · schema v1 · pii pii-v1
Full breach record for Wolf Haldenstein Adler Freeman & Herz LLP →Wolf Haldenstein Adler Freeman & Herz LLP, a law firm, notified the Maryland Attorney General of a cybersecurity incident discovered on December 13, 2023. An unauthorized actor accessed files containing names, Social Security numbers, employee IDs, and medical diagnosis/claim information. Approximately 79,732 Maryland residents were affected. The firm engaged a cybersecurity firm, secured its network, and offered credit monitoring.
Leak gap clock✗ Leak >180d23 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
A leak claim by black_basta about this victim predates this filing by 691 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_747af5a683f6a74fMaryland State AGfiled 2025-11-13Candidate
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376252.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- f00ff509fe3e0aa7b2747bfc5b0532d5c1adfb03768dd757ec177a054e2bba51
Reporting entity
- Name
- Wilson, Elser, Moskowitz, Edelman & Dicker LLPnorm: wilson elser moskowitz edelman dicker
Victim entity
- Name
- Wolf Haldenstein Adler Freeman & Herz LLPnorm: wolf haldenstein adler freeman herz
- Domain
- whafh.com
Incident
- Discovered
- Dec 13, 2023
- Materiality determined
- —
- Notification sent
- Jan 10, 2025
- Affected individuals
- 79,732
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- External
Compliance
- Time to disclose
- 23 months(701 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.