DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingStolen CredentialsMulti-Stage ChainCustomer Data InvolvedPIIIdentity (basic)CredentialsLowContained

Goodspeed & Merrill

bd_acfcc7e053dca0e0 · schema v1 · pii pii-v1

Severity

Low

Discovered

Nov 7, 2020

Filed

Jan 22, 2021

To disclose

11 weeks

Affected

7state residents only

Linked

2 filings

Confidence

65%
Full breach record for Goodspeed & Merrill

Goodspeed & Merrill d/b/a Rome LLC notified Montana residents of an email account compromise. Unauthorized access occurred between March 23 and August 28, 2020, likely via phishing. Personal information may have been accessed. The company engaged forensic investigators, secured accounts, and offered one year of identity monitoring.

Incident timeline

undetected · 229 days
discovery → filing · 11 weeks / 76 days

Mar 23, 2020

Begins

Nov 7, 2020

Discovered

Jan 22, 2021

Filed

vs. sector median

8 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Maine State AGJan 22 · first
Montana State AGJan 22 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.