Baldwin EMC
ent_0c6d0ab223ffc898517d46d7
Disclosures
4
State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
6,464
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Baldwin EMC
- Normalized
- baldwin emc— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- baldwinemc.com
Disclosure history (4)newest first
- 🏎️Indiana State AGas victim2026-01-26
EMC Water LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-09 and was reported on 2026-01-26. 165 Indiana residents were affected. 6,464 individuals affected in total.
- 🦞Maine State AGas victim2026-01-26
EMC Water LLC notified 121 Maine residents of a breach in which an unauthorized actor exploited a previously unknown vulnerability in Oracle E-Business Suite to exfiltrate files between Aug 9-18, 2025. Discovered late Nov 2025; review completed Jan 9, 2026. Exposed data: names and SSNs. Oracle patch applied post-discovery. One-year Epiq credit monitoring offered.
- ⛰️New Hampshire State AGas victim2026-01-26
EMC Water, LLC notified the New Hampshire Attorney General of a security incident involving Oracle E-Business Suite. An external actor exploited a previously unknown vulnerability (zero-day) in Oracle EBS to exfiltrate data between August 9 and 18, 2025. EMC Water learned of the incident in late November 2025. The breach affected 112 New Hampshire residents, exposing names and Social Security numbers. Notification letters were mailed on January 26, 2026, offering one year of credit monitoring. EMC Water applied the relevant Oracle patch and engaged third-party cybersecurity professionals and law enforcement.
- 🍁Vermont State AGas victim2026-01-26
EMC Water LLC notified consumers of a data breach where an unauthorized actor exploited a previously unknown vulnerability (zero-day) in Oracle E-Business Suite to exfiltrate names and Social Security numbers between August 9-18, 2025. EMC applied the vendor patch, engaged third-party forensics, notified law enforcement, and offered one year of credit monitoring.