MCLANE MIDDLETON, PROFESSIONAL ASSOCIATION
ent_019e1192747f2046b77a8d985ca7fd5a
Disclosures
17
State AG · 4 jurisdictions
Multi-filing incidents
13
incidents joining 2+ filings here
Max affected reported
70,168
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MCLANE MIDDLETON, PROFESSIONAL ASSOCIATION
- Normalized
- mclane middleton professional— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 54930045DRGM8SZO7N42
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (17)newest first
- New Hampshire State AGas reporting2026-04-30
Quality Carton & Converting, LLC, a New Hampshire-based manufacturer, reported a ransomware incident involving the Akira group. Discovered on February 10, 2026, the breach resulted in the exfiltration of employee and client PII, including SSNs and financial account data. Approximately 29 New Hampshire residents were affected. QCC engaged forensic specialists, notified law enforcement, and provided 24 months of credit monitoring via Experian. The incident status is contained.
- Maine State AGas reporting2024-11-11
BBS Financial Services, LLC reported a ransomware incident where the threat actor BianLian exfiltrated data from its network. The breach affected approximately 70,168 individuals, including 1,404 Maine residents. Compromised data included tax records, payroll information, and medical billing records containing PII, SSNs, financial account numbers, and PHI. BBS paid a ransom and provided 2 years of credit monitoring to affected individuals.
- Maine State AGas reporting2024-06-27
Counseling Associates of New London, PLLC (a NH-based healthcare provider) reported a data breach to the Maine AG. The breach occurred on and was discovered on 03/25/2024, and notifications were sent electronically on 04/25/2024. A total of 102 persons were affected, including 1 Maine resident. The filing categorized the breach as 'Other' without specifying the attack vector or data types. Affected individuals were offered 2 years of IDX 1-bureau identity theft protection and credit monitoring.
- New Hampshire State AGas reporting2022-05-25
The Town of Middleton, NH, accidentally disclosed unredacted employee SSNs to a requester on Feb 28, 2022. Discovered March 1, 2022. 43 residents affected. Notices mailed May 23, 2022. Credit monitoring offered.
- Montana State AGas reporting2022-03-21
Roy & Rurak, a tax preparation firm, disclosed a ransomware incident affecting 2 Montana residents. Unauthorized remote access was gained to Medaglia & Murphy’s network on or before Dec 29, 2021. The firm paid a ransom after negotiations with the attacker facilitated by the USSS. Affected data included SSNs, financial accounts, and tax returns. Notices were mailed March 16, 2022, offering two years of credit monitoring.
- New Hampshire State AGas reporting2022-03-21
Medaglia & Murphy, Inc. reported a data security incident discovered on December 29, 2021, where a third party gained unauthorized remote access to its network. The incident affected 3,244 New Hampshire residents (2,807 adults and 437 minors). The attacker demanded a ransom, which was paid after negotiations facilitated by the USSS. Data accessed likely included SSNs, financial account numbers, and tax returns. Affected individuals received notification on March 16, 2022, and were offered 2 years of credit monitoring.
- New Hampshire State AGas reporting2022-02-18
Coastal Family Nutrition LLC (CFN) reported a targeted malware incident in December 2021 affecting 319 New Hampshire residents, including 290 minors. Malware scanned files on a CFN computer and a connected OneDrive account. No data exfiltration or ransom payment was confirmed. CFN engaged forensic experts, deactivated the device, and offered 2 years of Experian IdentityWorks monitoring to affected families.
- New Hampshire State AGas reporting2021-01-28
SapphireFoxxBeyond.com notified the NH Attorney General of a breach affecting 172 NH residents. Malware installed in June 2020 captured keystrokes (credentials) and credit card data entered between June and Dec 12, 2020. The site notified users, reset passwords, and offered 2 years of Experian IdentityWorks. The site implemented additional security controls and threat detection software.
- New Hampshire State AGas reporting2021-01-26
ConvenientMD Urgent Care notified the NH Attorney General of a data security breach involving 130 New Hampshire residents. Between December 18 and 21, 2020, the company sent emails notifying individuals of available coronavirus test results. Due to a misconfiguration, all recipient email addresses were placed in the 'To' field rather than 'Bcc', exposing the email addresses of other recipients. This allowed recipients to see that others had been tested for coronavirus. No actual test results were included in the emails. ConvenientMD has corrected its email procedures.
- New Hampshire State AGas victim2020-12-23
McLane Middleton, Professional Association notified the NH AG of a security incident involving spoofed emails containing malware on employee desktops. While no unauthorized access to PII was confirmed, SSNs and financial account numbers were present in affected emails. 449 NH residents (employees and non-employees) were notified and offered 2 years of Experian IdentityWorks. Investigation concluded mid-August 2020; notifications sent Dec 2020.
- Massachusetts State AGas victim2020-12-15
McLane Middleton reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-12-15. 107 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2020-12-09
McLane Middleton, a professional services firm, reported a data breach affecting 15 Maine residents. The breach, which occurred and was discovered on August 17, 2020, was described as an external system breach or hacking incident. The compromised information included names or other personal identifiers in combination with Social Security Numbers. Affected individuals were notified on December 8, 2020, and offered 24 months of 3-bureau credit monitoring services.
- Maine State AGas reporting2020-11-19
Proctor Academy, an educational institution, reported an external system breach that occurred on June 1, 2020, and was discovered on September 29, 2020. The breach affected 691 individuals, compromising names and Social Security Numbers. Affected individuals were notified on November 7, 2020, and offered identity theft protection services.
- New Hampshire State AGas reporting2020-11-16
The City of Keene, NH notified residents of a data breach involving its third-party check processing vendor, Technology Management Resources, Inc. (TMR). An unauthorized individual accessed TMR's database from June 1 to July 1, 2020, viewing scanned check images containing names, addresses, and bank account/routing numbers for 4,360 NH residents and 732 organizations. The City offered credit monitoring services and advised victims to monitor accounts.
- New Hampshire State AGas reporting2020-11-12
Keolis Commuter Services experienced a ransomware event on October 10, 2020, affecting 869 New Hampshire residents. The incident involved the encryption of files and subsequent exfiltration of employee and dependent PII, including SSNs, driver's license numbers, and medical data. Keolis contained the breach by deactivating the network, notified law enforcement, and engaged forensic experts. Notifications were sent on November 10, 2020, offering two years of credit monitoring.
- New Hampshire State AGas reporting2018-01-26
Kraus Associates, Inc. d/b/a AK Associates notified the NH AG of a ransomware incident (Tastylock) affecting one computer. The incident occurred on Dec 23, 2017, and was discovered on Dec 26, 2017. PII of 132 individuals (employees, spouses, dependents) was on the computer, including SSNs and bank account numbers. No ransom was paid. Data was restored from backups. Forensic investigators concluded data export was unlikely but not ruled out. Notices sent Jan 26, 2018.
- New Hampshire State AGas reporting2017-08-09
New Hampshire Retirement System (NHRS) notified the NH Attorney General on August 9, 2017, of a data security incident affecting 45 retirees. An unauthorized party established fraudulent online accounts in the NHRS 'My Account' portal in early July 2017 to redirect pension payments to Green Dot Bank accounts. NHRS detected the fraud before payments were processed, shutting down the function and deactivating the accounts. Affected data included bank account numbers, names, addresses, DOBs, and last 4 digits of SSNs. No pension funds were lost. NHRS reported to the Secret Service and NH State Police, offered credit monitoring, and implemented stricter authentication controls.