HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Brumbaugh Wealth Management
bd_aa4cd0d83ff54bdf · schema v1 · pii pii-v1
Full breach record for Brumbaugh Wealth Management →Brumbaugh Wealth Management notified the Maryland AG of an email event affecting 21 Maryland residents. Unauthorized access to an employee's email account occurred between July 3 and July 8, 2024. Impacted data included names, SSNs, driver's license numbers, and financial account information. Brumbaugh secured accounts, notified law enforcement, and provided one year of credit monitoring via Experian.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed21 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376181.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 9a3b94a6a6338b5f3267e2725c535f5ebb03e37e7dfbb5a4c9e98168e83a0492
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Brumbaugh Wealth Managementnorm: brumbaugh wealth management
Incident
- Discovered
- Jul 3, 2024
- Materiality determined
- —
- Notification sent
- Jan 13, 2025
- Affected individuals
- 21
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Maryland Attorney General's Office
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 months(498 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.