J.M. Forbes & Co.
bd_af0270378c395134 · schema v1 · pii pii-v1
Full breach record for J.M. Forbes & Co. →JM Forbes & Co detected suspicious activity on its email system on November 17, 2025, which was determined to be a business email compromise attempt via social engineering. An unauthorized external party accessed an employee email account containing personal information, including names, addresses, Social Security numbers, and account numbers. The firm contained the incident before fraudulent transactions occurred. Affected individuals are offered two years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 17, 2025
Discovered
Apr 7, 2026
Filed
vs. sector median
+1 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Vermont State AGbd_2d8fdc40759510b02026-04-07Candidate
- New Hampshire State AGbd_66f15480d78ef9f62026-04-07Verified
- Maine State AGbd_ba4b31877e8d09b12026-04-07Verified by operator
- Nebraska State AGbd_98d54460da9f9c8f2026-07-06 · +90dVerified
Show 1 more filing ↓Show fewer ↑up to 90d gap
- New Hampshire State AGbd_a5dc2e414705c04d2026-07-06 · +90dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Apr 7 (VT), last Jul 6 (NH) — a 90-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.