ERMI
bd_9f7664f300747a66 · schema v1 · pii pii-v1
Full breach record for ERMI →ERMI, LLC reported a cybersecurity incident in Massachusetts where an unauthorized individual gained access to employee email accounts between February 15, 2025, and August 14, 2025. The breach potentially exposed personal information, including government IDs and financial account numbers, of a limited number of individuals. ERMI engaged external cybersecurity professionals, contained the incident, and offered 24 months of complimentary credit monitoring services to affected parties.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 15, 2025
Begins
Jul 25, 2025
Discovered
Apr 17, 2026
Scope determined
May 26, 2026
Filed
vs. sector median
+31 wks slower
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- HHS OCRbd_5f4b21c440602c3c2026-05-26Verified
- California State AGbd_6f3c9fcbecab88f22026-05-26Verified
- Nebraska State AGbd_a8dfc551501a46792026-05-26Verified
- Vermont State AGbd_e4c668bd9e1677852026-05-26Verified
Show 3 more filings ↓Show fewer ↑up to 25d gap
- Texas State AGbd_9d24b056d9c464ff2026-05-28 · +2dVerified
- South Carolina State AGbd_762f7d904880c3cd2026-05-29 · +3dVerified
- Illinois State AGbd_e6dcd1aa6d5100a32026-05-01 · +25dCandidate
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing May 1 (IL), last May 29 (SC) — a 28-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.