HackingDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
InterCon Construction, Inc.
bd_a6ea95c84dce39c8 · schema v1 · pii pii-v1
Full breach record for InterCon Construction, Inc. →InterCon Construction, Inc. notified the Maryland Attorney General of a cybersecurity incident where an unauthorized third party accessed systems between Nov 9-20, 2024. The incident affected 8 Maryland residents, exposing names and Social Security Numbers. InterCon secured the network, notified federal law enforcement, and provided 2 years of credit monitoring to affected individuals.
Maryland clock⏱ MD AG >30d10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by hunters_international about this victim predates this filing by 72 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_130aa61ef87a5c7cLeak Sitehunters_internationalfiled 2024-12-03(57d gap)Verified
- bd_5e8fadd8989ae7b9Leak Sitehunters_internationalfiled 2024-11-19(72d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_07da051516d760a9Vermont State AGfiled 2025-01-30Verified by operator
- bd_582a084eaf48919fMaine State AGfiled 2025-01-30Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376268.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2025
- Raw hash
- 2e68f196e199c47913a46a6db37ef6cd27f49296fe014da7cd777bfe80550522
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- InterCon Construction, Inc.norm: intercon construction
- Domain
- intercon-const.com
Incident
- Discovered
- Nov 19, 2024
- Materiality determined
- Dec 6, 2024
- Notification sent
- Jan 30, 2025
- Affected individuals
- 8
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement regarding the eventProviding written notice of this incident to relevant state regulators, as necessary, and to the three major credit reporting agencies, Equifax, Experian, and TransUnion
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- MD AG >30dLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.