HackingData ExfiltratedDelayed DiscoveryPIIIDENTITY_BASICLowActive
Rhodes, Young, Black, and Duncan
bd_db700247ccd17ccf · schema v1 · pii pii-v1
Full breach record for Rhodes, Young, Black, and Duncan →Rhodes, Young, Black, and Duncan (RYBD), a tax and accounting services firm, disclosed a cybersecurity incident involving unauthorized access to a backup server. The breach occurred on September 17, 2025, and was detected on October 12, 2025. Data was exfiltrated prior to detection. RYBD notified affected individuals on May 27, 2026, offering credit monitoring and identity theft recovery services. The specific data types compromised are redacted in the source text.
Massachusetts clock✗ MA AG >90d37 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b25566f2bd3200e9New Hampshire State AGfiled 2026-06-29(2d gap)Candidate
- bd_393ca5d3b08226e8Indiana State AGfiled 2026-06-26(5d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1134-rhodes-young-black-and-duncan/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2026
- Raw hash
- a3b2843310a44e626dbb9785bcde3ccfa594cfa2d698eaaf92f403534ac1d29d
Reporting entity
- Name
- Rhodes, Young, Black, and Duncannorm: rhodes young black and duncan
Victim entity
- Name
- Rhodes, Young, Black, and Duncannorm: rhodes young black and duncan
Incident
- Discovered
- Oct 12, 2025
- Materiality determined
- —
- Notification sent
- May 27, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 37 weeks(262 days from discovery to filing)
- Compliance flags
- MA AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.