Social EngineeringPhishingStolen CredentialsRansom DemandedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Olinsky & Associates, PLLC
bd_972f5dbdce5657a9 · schema v1 · pii pii-v1
Full breach record for Olinsky & Associates, PLLC →Olinsky & Associates, PLLC notified the Maryland Attorney General of a phishing attack discovered on January 28, 2025. Criminal actors used stolen credentials to access a shared drive, compromising personal, health, and financial data of two Maryland residents. Olinsky engaged forensic investigators, notified the FBI and police, and provided two years of credit monitoring to affected individuals.
Maryland clock⏱ MD AG >30d6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_afb7511ee4750006New Hampshire State AGfiled 2025-03-11Verified
- bd_cdcde3b568db9fd7Montana State AGfiled 2025-03-11Candidate
- bd_f4c5a4ecf5731249Indiana State AGfiled 2025-03-11Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376530.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 11, 2025
- Raw hash
- fc2aa2b66523f471488c917c1507ab25b8e38f8b53d395d80b00f895907ae861
Reporting entity
- Name
- Olinsky & Associates, PLLCnorm: olinsky associates
Victim entity
- Name
- Olinsky & Associates, PLLCnorm: olinsky associates
Incident
- Discovered
- Jan 28, 2025
- Materiality determined
- —
- Notification sent
- Mar 11, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to the policeReported this incident to the FBI
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- MD AG >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.