MalwareRansomwareData EncryptedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPIIHighContained
Sprechman & Associates, P.A.
bd_b0ce2ae64f632975 · schema v1 · pii pii-v1
Full breach record for Sprechman & Associates, P.A. →Berman & Rabin, P.A. notified the Maryland Attorney General on January 28, 2025, of a cybersecurity incident occurring between July 5 and July 8, 2024. An unknown actor gained access to systems and encrypted files (ransomware). The incident potentially affected 2,874 Maryland residents, exposing names, SSNs, driver's license numbers, financial account info, and medical/health insurance data. Berman & Rabin secured its environment, notified federal law enforcement, and provided 12 months of credit monitoring through IDX to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,874 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376254.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- bb6b7155364ed07fdb10b739e84fe7d67bb558c00449961c1616dd3fa8f62cfa
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Sprechman & Associates, P.A.norm: sprechman associates
Incident
- Discovered
- Jul 8, 2024
- Materiality determined
- —
- Notification sent
- Jan 28, 2025
- Affected individuals
- 2,874
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 months(493 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.