MalwareRansomwareData EncryptedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumActive
PMA Consultants
bd_fd0865727c08d584 · schema v1 · pii pii-v1
Full breach record for PMA Consultants →PMA Consultants notified the Maryland AG of a ransomware attack discovered on May 7, 2024. The incident affected 5 Maryland residents, exposing names, SSNs, alien registration numbers, passport numbers, driver's license numbers, and health insurance information. PMA engaged forensic specialists, reported to federal law enforcement, and offered 12 months of credit monitoring. The investigation and data review were ongoing at the time of notification.
Maryland clock✗ MD AG >90d45 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_7b8da585f4ff4455Maine State AGfiled 2025-03-17Verified
- bd_7d2860b96ee0522aNew Hampshire State AGfiled 2025-03-17Verified
- bd_93723ad4fd281834Indiana State AGfiled 2025-03-17Verified
- bd_e55973011bb404beMaine State AGfiled 2025-01-30(46d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 46d gap
- bd_fee1b469d6f3bacdNew Hampshire State AGfiled 2025-01-30(46d gap)Candidate
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376559.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 17, 2025
- Raw hash
- 3f75eb24539aa586fc2000503cdaa7fee055ae9ce7137e059533ccc1a9aeeb17
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- PMA Consultantsnorm: pma consultants
Incident
- Discovered
- May 7, 2024
- Materiality determined
- —
- Notification sent
- Mar 17, 2025
- Affected individuals
- 5
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this incident to federal law enforcement
Compliance
- Time to disclose
- 45 weeks(314 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.