HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Kafene Customer
bd_ec7798d922f15113 · schema v1 · pii pii-v1
Full breach record for Kafene Customer →Kafene, Inc. notified the Maryland Attorney General of a data security incident discovered on November 22, 2024. An unauthorized actor gained access to the network and potentially downloaded files containing personal information, including names, SSNs, driver's license numbers, passport numbers, and dates of birth. 19 Maryland residents were notified. Kafene engaged forensic investigators, reported the incident to the FBI, and provided credit and identity monitoring services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed19 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376182.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 075d8aa518a40d8fabfd21a4f7de430b8565d088d2e75b604929e4d3bce08cc9
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Kafene Customernorm: kafene customer
- Domain
- customer.kafene.com
Incident
- Discovered
- Nov 22, 2024
- Materiality determined
- —
- Notification sent
- Jan 8, 2024
- Affected individuals
- 19
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the incident to the FBI
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 51 weeks(356 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.