Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryPIILowResolved
PEÑA BRIONES MCDANIEL & CO.
bd_a214ab7508cc6169 · schema v1 · pii pii-v1
Full breach record for PEÑA BRIONES MCDANIEL & CO. →On or about February 12, 2025, an unauthorized individual may have gained access to an employee email account at Peña Briones McDaniel & Co., PC, an El Paso, TX-based professional corporation. The breach was discovered on August 20, 2025 following an extensive forensic investigation. A total of 1,757 individuals were affected, including 1 Maine resident. Affected individuals were offered 12-month IDX identity protection services.
Leak gap clock⏱ Leak >90d27 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by akira about this victim predates this filing by 154 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_86ae20157535d2f4Leak Siteakirafiled 2025-04-15(154d gap)Verified by operator
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/2cf1affe-51cd-4f48-bb4a-ab88d84f3b42.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 16, 2025
- Raw hash
- 70d4663b275f9d4fa7c944132018073bffa6d314251dd9c9b3eb1d53855087e2
Reporting entity
- Name
- PEÑA BRIONES MCDANIEL & CO.norm: pena briones mcdaniel
- Domain
- cpaelpaso.com
- Industry
- Other Commercial
Victim entity
- Name
- PEÑA BRIONES MCDANIEL & CO.norm: pena briones mcdaniel
- Domain
- cpaelpaso.com
- Industry
- Other Commercial
Incident
- Discovered
- Aug 20, 2025
- Materiality determined
- —
- Notification sent
- Sep 16, 2025
- Affected individuals
- 1
- Data types
- PII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Maine Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- Leak >90dME AG ≤30d · 27d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Aug 20, 2025→ Filed with AG: Sep 16, 202527d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.