Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Hermann Financial Services
bd_a930c1b5b1f086d8 · schema v1 · pii pii-v1
Full breach record for Hermann Financial Services →Hermann Financial Services, Inc. notified affected individuals in multiple states (including DE, CT, MD, NY, RI, NC, DC, WV) of a phishing incident targeting a single employee email account. Unauthorized access occurred between June 13, 2025, and June 25, 2025. The company determined on September 15, 2025, that the compromised emails contained recipients' personal information. Kroll was engaged to provide complimentary identity monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3eee47109c30e0fbMaine State AGfiled 2025-10-15Candidate
- bd_972bc365c4d0aff7Vermont State AGfiled 2025-10-15Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2026/01/HFS-Delaware-Attachment.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 15, 2025
- Raw hash
- 19cd282afb7ab6735cadb2bfd3c7e1e7382a750deb6545a71dfd7d73bb156715
Reporting entity
- Name
- Hermann Financial Servicesnorm: hermann financial
Victim entity
- Name
- Hermann Financial Servicesnorm: hermann financial
Incident
- Discovered
- Jun 13, 2025
- Materiality determined
- —
- Notification sent
- Sep 15, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 18 weeks(124 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.