Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTAUTHENTICATIONFINANCIAL_ACCOUNTMediumContained
FlexCare, LLC
bd_d5a1387edf3c35a9 · schema v1 · pii pii-v1
Full breach record for FlexCare, LLC →FlexCare, LLC reported a cybersecurity incident to the Maryland Attorney General on March 5, 2025. The breach involved unauthorized access to an employee's email account starting around October 9, 2024, likely via a phishing attack. The incident affected 9 Maryland residents, exposing names, Social Security numbers, system access information, and health insurance data. FlexCare secured the account, notified affected individuals, and provided two years of credit monitoring through IDX.
Maryland clock✗ MD AG >90d21 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_16052ffaaad62029New Hampshire State AGfiled 2025-03-05Verified
- bd_50d0344a5a950db5Maine State AGfiled 2025-03-05Candidate
- bd_708228ea66f830f4Indiana State AGfiled 2025-03-05Verified
- bd_f478e208364745e5Vermont State AGfiled 2025-03-05Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376529.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 5, 2025
- Raw hash
- 1932905db118cf8cc2178394ae50f0297b72e2039a9a83689edec88161351d9e
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- FlexCare, LLCnorm: flexcare
- Domain
- flexcarestaff.com
Incident
- Discovered
- Oct 9, 2024
- Materiality determined
- —
- Notification sent
- Mar 5, 2025
- Affected individuals
- 9
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTAUTHENTICATIONFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 21 weeks(147 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.