HackingCustomer Data InvolvedIDENTITY_BASICMediumContained
KerberRose
bd_b053396543ca5b5e · schema v1 · pii pii-v1
Full breach record for KerberRose →KerberRose S.C., a financial services entity based in Shawano, WI, reported an external system breach (hacking) occurring on April 29, 2026, discovered on May 1, 2026. The incident affected a total of 27,076 individuals, including 4 Maine residents. The breach involved the acquisition of names and personal identifiers. KerberRose notified affected individuals in writing on May 29, 2026, and provided 24 months of identity theft protection services through TransUnion Cyberscout.
Maine clockDiscovered May 1, 2026 → Filed with AG May 29, 202628d ✓ ME AG ≤30d28 days discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_971065d86a026703Vermont State AGfiled 2026-05-29Verified
- bd_b5592268966c1f84Indiana State AGfiled 2026-05-29Verified
- bd_f7e6792d830978eeNew Hampshire State AGfiled 2026-05-29Verified
- bd_df731ff4766cb144Massachusetts State AGfiled 2026-05-01(28d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/a0b45e9a-7d59-4bad-8b1f-b1c6cc74ba39.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 29, 2026
- Raw hash
- 4d4a42b47838af9fb3da6655b3c4a58f8453dfa63e6c31c912289ec704c928d9
Reporting entity
- Name
- Godfrey & Kahn: GKLawnorm: godfrey kahn gklaw
- Domain
- gklaw.com
Victim entity
- Name
- KerberRosenorm: kerberrose
- Domain
- kerberrose.com
- Industry
- financial_services
Incident
- Discovered
- May 1, 2026
- Materiality determined
- —
- Notification sent
- May 29, 2026
- Affected individuals
- 27,076
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 28d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 1, 2026→ Filed with AG: May 29, 202628d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.