Rhodes, Young, Black, and Duncan
bd_db700247ccd17ccf · schema v1 · pii pii-v1
Full breach record for Rhodes, Young, Black, and Duncan →2 incidents on fileRhodes, Young, Black, and Duncan (RYBD), a tax and accounting services firm, disclosed a cybersecurity incident involving unauthorized access to a backup server. The breach occurred on September 17, 2025, and was detected on October 12, 2025. Data was exfiltrated prior to detection. RYBD notified affected individuals on May 27, 2026, offering credit monitoring and identity theft recovery services. The specific data types compromised are redacted in the source text.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 17, 2025
Begins
Oct 12, 2025
Discovered
Jul 14, 2026
Filed
vs. sector median
+22 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- New Hampshire State AGbd_b25566f2bd3200e92026-06-29 · +15dCandidate
- Massachusetts State AGbd_29db5ca2b0472d4d2026-06-27 · +17dVerified
- Massachusetts State AGbd_62dd36e87f691f132026-08-01 · +18dVerified
- Nebraska State AGbd_09615de228572e2f2026-06-26 · +18dVerified
Show 1 more filing ↓Show fewer ↑up to 18d gap
- Indiana State AGbd_393ca5d3b08226e82026-06-26 · +18dVerified
Filing propagation · 6 filings · 4 states
View merged incident ↗Pattern: first filing Jun 26 (NE), last Aug 1 (MA) — a 36-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.