Clustered 5 filings across 3 jurisdictions · filing window Dec 19, 2025 → Mar 12, 2026. View entity profile → Other incidents for this victim →
incident inc_0f7070bea30d4ab1 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
PII · Government ID
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
IN ME NH
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Mar 28, 2025
When the intrusion reportedly occurred, per the linked filings
Apr 3, 2025
Reported by NEW HAMPSHIRE AG, MAINE AG filings
Supplemental notice to NH AG by Mullen Coughlin LLC on behalf of McElroy, Deutsch, Mulvaney & Carpenter LLP. Cyberattack occurred March 28-April 1, 2025; discovered April 3, 2025. Affected 2 NH residents with name and SSN. Initial notice Dec 19, 2025. Credit monitoring provided.
Affected (this filing): 2
MDMC (law firm, NJ) suffered a cyberattack Mar 28–Apr 1, 2025; discovered Apr 3, 2025. Investigation completed Dec 4, 2025 confirmed unauthorized actors accessed/acquired personal data (name, SSN). Five Maine residents affected. Prior notice sent Dec 19, 2025; supplemental notice Mar 12, 2026. Twelve months of credit monitoring offered via Epiq.
Affected (this filing): 5
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
McElroy Deutsch Mulvaney & Carpenter LLP reported a data breach to the Indiana Attorney General. The breach occurred on 2025-03-28 and was reported on 2025-12-19. 28 Indiana residents were affected. 6,690 individuals affected in total.
Affected (this filing): 6,690
McElroy, Deutsch, Mulvaney & Carpenter LLP (MDMC) notified the New Hampshire Attorney General of a cyberattack affecting one NH resident. Unauthorized access to MDMC systems occurred March 28–April 1, 2025. MDMC detected suspicious activity on April 3, 2025, and confirmed on December 4, 2025, that names and Social Security numbers were accessed. MDMC notified federal law enforcement, provided 12 months of credit monitoring via Epiq, and is reviewing security policies.
Affected (this filing): 1
McElroy, Deutsch, Mulvaney & Carpenter LLP (MDMC), a New Jersey-based law firm, experienced an external cyberattack between March 28–April 1, 2025, discovered on April 3, 2025. Unauthorized actors accessed or acquired files containing names and Social Security numbers. The comprehensive file review was completed December 4, 2025, identifying 3 Maine residents affected. MDMC secured its network, notified federal law enforcement, and offered 12 months of credit monitoring via Epiq.
Affected (this filing): 3