J.M. Forbes & Co.
ent_0c7f8c45238a84be53a1654b
Disclosures
6
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
584
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- J.M. Forbes & Co.
- Normalized
- jm forbes— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- jmforbes.com
Disclosure history (6)newest first
- Nebraska State AGas victim2026-07-06
JM Forbes and Co experienced a security incident on November 17, 2025, involving suspicious activity on its email system. An unauthorized external party gained access to an employee email account via social engineering (business email compromise attempt) to redirect payments. The attempt was stopped before fraudulent transactions occurred. Affected data included names, addresses, Social Security numbers, and account numbers. JM Forbes notified affected individuals starting April 8, 2026, and offered two years of complimentary credit monitoring.
- New Hampshire State AGas victim2026-07-06
JM Forbes and Co. filed a supplemental notice to the New Hampshire Attorney General regarding a business email compromise incident. An unauthorized external party gained access to an employee email account via social engineering/phishing on November 17, 2025. The incident affected 45 individuals (26 NH residents), exposing names, addresses, SSNs, and account numbers. No fraudulent transactions occurred. JMF offered 2 years of credit monitoring.
- Vermont State AGas victim2026-04-07
J.M. Forbes & Co. detected suspicious activity on its email system on November 17, 2025, which was part of an attempted business email compromise via social engineering. An unauthorized external party accessed an employee email account. The compromised account may have contained personal information including names, addresses, Social Security numbers, and account numbers. The company contained the incident, preventing fraudulent transactions, and is offering two years of credit monitoring to affected individuals.
- New Hampshire State AGas victim2026-04-07
JM Forbes & Co., a wealth management firm, notified the New Hampshire Attorney General of a security incident affecting 19 residents. On November 17, 2025, suspicious activity was detected on an employee email account. Investigation determined unauthorized access occurred via social engineering (business email compromise). Affected data included names, addresses, SSNs, and account numbers. No fraudulent transactions occurred. JMF provided two years of credit monitoring and enhanced safeguards.
- Massachusetts State AGas victim2026-04-07
JM Forbes & Co detected suspicious activity on its email system on November 17, 2025, which was determined to be a business email compromise attempt via social engineering. An unauthorized external party accessed an employee email account containing personal information, including names, addresses, Social Security numbers, and account numbers. The firm contained the incident before fraudulent transactions occurred. Affected individuals are offered two years of credit monitoring.
- Maine State AGas victim2026-04-07
JM Forbes & Co. reported a business email compromise incident on November 17, 2025, where an external party gained access to an employee email account via social engineering. The breach affected 584 individuals, including 23 Maine residents, exposing names, addresses, SSNs, and account numbers. JM Forbes contained the incident, engaged forensic experts, and provided 24 months of credit monitoring to affected individuals. Notification was sent on April 7, 2026.