McElroy, Deutsch, Mulvaney & Carpenter LLP
bd_bd3f74df05a359e3 · schema v1 · pii pii-v1
Full breach record for McElroy, Deutsch, Mulvaney & Carpenter LLP →McElroy, Deutsch, Mulvaney & Carpenter LLP (MDMC) notified the New Hampshire Attorney General of a cyberattack affecting one NH resident. Unauthorized access to MDMC systems occurred March 28–April 1, 2025. MDMC detected suspicious activity on April 3, 2025, and confirmed on December 4, 2025, that names and Social Security numbers were accessed. MDMC notified federal law enforcement, provided 12 months of credit monitoring via Epiq, and is reviewing security policies.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 28, 2025
Begins
Apr 3, 2025
Discovered
Dec 19, 2025
Filed
vs. sector median
+18 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Indiana State AGbd_698f1a0d029620162025-12-19Verified
- Nebraska State AGbd_6da1ae289ac345962025-12-19Verified
- Maine State AGbd_efd18d3b3c3e05362025-12-19Candidate
- New Hampshire State AGbd_03b000a29a602b0c2026-03-12 · +83dCandidate
Show 1 more filing ↓Show fewer ↑up to 83d gap
- Maine State AGbd_df428c93170c98cf2026-03-12 · +83dVerified
Filing propagation · 6 filings · 4 states
View merged incident ↗Pattern: first filing Dec 19 (IN), last Mar 12 (ME) — a 83-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.