Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Steven Miller & Co. LLC
bd_a27c7858cfaad7f9 · schema v1 · pii pii-v1
Full breach record for Steven Miller & Co. LLC →Steven Miller & Co. LLC notified the Maryland AG of a data breach impacting 5 Maryland residents. On July 8, 2024, an unauthorized actor accessed a web-based accounting platform via a phishing scam, acquiring names, SSNs, and driver's licenses. The company engaged forensic specialists, notified affected individuals on Jan 21, 2025, and offered 12 months of credit monitoring. Remediation included MFA implementation and password resets.
Maryland clock✗ MD AG >90d29 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_8138ad48c954de23Maine State AGfiled 2025-01-29Candidate
- bd_c66c03f8089ac597New Hampshire State AGfiled 2025-01-27(2d gap)Verified
- bd_c7eb88ee1f2b3558Indiana State AGfiled 2025-01-21(8d gap)Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376259.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 29, 2025
- Raw hash
- 4583defc6136483fed3bd4240a641a7a0d7cc8703c9326df2e53bd95c0559470
Reporting entity
- Name
- Steven Miller & Co. LLCnorm: steven miller
Victim entity
- Name
- Steven Miller & Co. LLCnorm: steven miller
Incident
- Discovered
- Jul 8, 2024
- Materiality determined
- —
- Notification sent
- Jan 21, 2025
- Affected individuals
- 5
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 29 weeks(205 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.