Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Frank Rimerman + Co LLP
bd_9b0eb6dcec2f1b21 · schema v1 · pii pii-v1
Full breach record for Frank Rimerman + Co LLP →Frank, Rimerman + Co. LLP (FRC) notified Maryland AG that an unauthorized third party compromised FRC's email environment on May 8, 2024, via a phishing incident. Personal information, including names and potentially government identifiers, was accessed from a compromised mailbox. FRC engaged forensic experts, notified law enforcement, and offered complimentary identity monitoring services to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376206.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 5aa2efc8316ccb276ceccc7e57550635cafffd69a31b37ecea1d686c966c8031
Reporting entity
- Name
- Frank Rimerman + Co LLPnorm: frank rimerman
Victim entity
- Name
- Frank Rimerman + Co LLPnorm: frank rimerman
Incident
- Discovered
- May 8, 2024
- Materiality determined
- —
- Notification sent
- Dec 26, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified law enforcement regarding this incident
- Initial access
- phishing_link
Compliance
- Time to disclose
- 18 months(554 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.