HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
KerberRose
bd_df731ff4766cb144 · schema v1 · pii pii-v1
Full breach record for KerberRose →KerberRose Wealth Management, LLC notified Massachusetts residents of a data security incident discovered on May 1, 2026. The breach potentially exposed customer names, addresses, Social Security numbers, financial account numbers, and dates of birth. KerberRose isolated the environment, engaged forensic investigators, and offered 24 months of credit monitoring via Cyberscout. No evidence of fraud was found at the time of notification.
Massachusetts clock✓ MA AG ≤30d≤1 day discovery → filing
⚠ filing dateThe stored discovery date equals the regulator filing date, so no genuine detection date was captured.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_971065d86a026703Vermont State AGfiled 2026-05-29(28d gap)Verified
- bd_b053396543ca5b5eMaine State AGfiled 2026-05-29(28d gap)Verified
- bd_b5592268966c1f84Indiana State AGfiled 2026-05-29(28d gap)Verified
- bd_f7e6792d830978eeNew Hampshire State AGfiled 2026-05-29(28d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-876-kerberrose-sc/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- 8da7c778a0c16fd9cc50a3c27029b3364d0004da81430346fd03ee759a51801b
Reporting entity
- Name
- KerberRosenorm: kerberrose
- Domain
- kerberrose.com
Victim entity
- Name
- KerberRosenorm: kerberrose
- Domain
- kerberrose.com
Incident
- Discovered
- May 1, 2026
- Materiality determined
- —
- Notification sent
- May 29, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- MA AG ≤30d
- Discovery-date grounding
- filing dateThe stored discovery date equals the regulator filing date, so no genuine detection date was captured.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.