Rhodes, Young, Black, and Duncan
ent_a522d02c7a7717afef801375
Disclosures
7
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,369
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Rhodes, Young, Black, and Duncan
- Normalized
- rhodes young black and duncan— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- Texas State AGas victim2026-08-25
Rhodes, Young, Black, and Duncan based in Duluth, Georgia, a financial services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-05-27 and reported on 2026-08-25. 330 Texas residents were affected. 3,650 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number). Consumers were notified via U.S. Mail.
- Massachusetts State AGas victim2026-08-01
Rhodes, Young, Black, and Duncan (RYBD), a tax and accounting services firm, detected unauthorized access to a backup server on October 12, 2025. Investigation revealed attackers accessed the network on September 17, 2025, and exfiltrated data. Affected individuals' personal information, including name and Social Security number, was compromised. RYBD activated its incident response plan, engaged outside cybersecurity and legal professionals, and is offering complimentary credit monitoring and identity theft recovery services to affected clients.
- Massachusetts State AGas victim2026-07-14
Rhodes, Young, Black, and Duncan (RYBD), a tax and accounting services firm, disclosed a cybersecurity incident involving unauthorized access to a backup server. The breach occurred on September 17, 2025, and was detected on October 12, 2025. Data was exfiltrated prior to detection. RYBD notified affected individuals on May 27, 2026, offering credit monitoring and identity theft recovery services. The specific data types compromised are redacted in the source text.
- New Hampshire State AGas victim2026-06-29
Rhodes, Young, Black, and Duncan (RYBD) notified the New Hampshire Attorney General of a cybersecurity incident affecting 7 NH residents. Unauthorized access occurred on September 17, 2025, via a SonicWall firewall vulnerability, leading to data exfiltration. RYBD detected the breach on October 12, 2025, secured the network, and engaged third-party forensic investigators. Personal information compromised included names, SSNs, and driver's license numbers. RYBD is offering complimentary credit monitoring to affected residents.
- Massachusetts State AGas victim2026-06-27
Rhodes, Young, Black, and Duncan issued a Massachusetts state AG breach notification offering credit monitoring and identity protection services to affected residents. The notice provides instructions for placing fraud alerts and security freezes with major credit bureaus (Equifax, Experian, TransUnion) and obtaining free credit reports. It also includes guidance on protecting medical information and filing complaints with the FTC. Specific details regarding the breach mechanism, dates, or data types are redacted or missing from the provided text.
- Nebraska State AGas victim2026-06-26
Rhodes, Young, Black, and Duncan (RYBD), a tax and accounting firm, notified Nebraska residents of a cybersecurity incident. Unauthorized access occurred on September 17, 2025, via a vulnerability in a SonicWall Firewall (supply chain compromise). Data was exfiltrated before detection on October 12, 2025. RYBD secured the network, engaged outside counsel and cybersecurity experts, and began notifying affected individuals around May 27, 2026. Compromised data likely includes personal information (PII). RYBD offers credit monitoring and identity theft recovery services.
- Indiana State AGas victim2026-06-26
Rhodes, Young, Black, and Duncan reported a data breach to the Indiana Attorney General. The breach occurred on 2025-09-17 and was reported on 2026-06-26. 3 Indiana residents were affected. 4,369 individuals affected in total.