ERMI
bd_a8dfc551501a4679 · schema v1 · pii pii-v1
Full breach record for ERMI →ERMI, LLC notified Nebraska residents that unauthorized access to employee email accounts occurred between Feb 15 and Aug 14, 2025. The breach was discovered on July 25, 2025, via phishing. Personal information of employees was potentially accessed. ERMI engaged cybersecurity professionals and offered credit monitoring/fraud alert guidance. Notices were sent around April 17, 2026.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 15, 2025
Begins
Jul 25, 2025
Discovered
May 26, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- HHS OCRbd_5f4b21c440602c3c2026-05-26Verified
- California State AGbd_6f3c9fcbecab88f22026-05-26Verified
- Massachusetts State AGbd_9f7664f300747a662026-05-26Verified
- Vermont State AGbd_e4c668bd9e1677852026-05-26Verified
Show 3 more filings ↓Show fewer ↑up to 25d gap
- Texas State AGbd_9d24b056d9c464ff2026-05-28 · +2dVerified
- South Carolina State AGbd_762f7d904880c3cd2026-05-29 · +3dVerified
- Illinois State AGbd_e6dcd1aa6d5100a32026-05-01 · +25dCandidate
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing May 1 (IL), last May 29 (SC) — a 28-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.