MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
American Plumbing & Heating Corporation
bd_cafced506e218c57 · schema v1 · pii pii-v1
Full breach record for American Plumbing & Heating Corporation →American Plumbing & Heating Corporation notified the Maryland AG of a December 18, 2024 incident where files were locked by a computer virus and copied without permission. Approximately 30 individuals nationwide (including 1 Maryland resident) were affected. Data exposed included names and Social Security numbers. The company engaged federal law enforcement, implemented technical security measures, and provided 24 months of credit monitoring via TransUnion.
Leak gap clock✗ Leak >180d7 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by lockbit2 about this victim predates this filing by 1120 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_22ab074d07dc14b8Leak Siteransomhubfiled 2025-01-10(24d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_11381bc8eadb3aeaNew Hampshire State AGfiled 2025-02-04Verified
- bd_df85026e11fe22e3Maine State AGfiled 2025-02-04Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376323.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 4, 2025
- Raw hash
- 0ba9a66655bf4940ffab5b06921cc3dd2ed60545c520dc7e0a9db0aa45079f77
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- American Plumbing & Heating Corporationnorm: american plumbing heating
- Domain
- amerplumb.com
Incident
- Discovered
- Dec 18, 2024
- Materiality determined
- —
- Notification sent
- Feb 4, 2025
- Affected individuals
- 30
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement regarding the event
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- Leak >180dMD AG >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.