Clustered 5 filings across 5 jurisdictions · filing window May 29, 2025 → May 30, 2025. View entity profile → Other incidents for this victim →
incident inc_33d6d92b6ba84bd3 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
IN ME NH TX VT
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Jan 1, 2024 → Jan 31, 2024
When the intrusion reportedly occurred, per the linked filings
Jan 1, 2024
Reported by NEW HAMPSHIRE AG filing
Mar 31, 2025
Reported by VERMONT AG, MAINE AG, TEXAS AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Hardin, Kundla, McKeon & Poletto, P.C. notified consumers of a data security incident involving a malicious encryption attack in January 2024. The incident resulted in unauthorized copying of files containing names and Social Security numbers. Approximately 12,063 individuals were notified. The firm engaged cybersecurity experts and is offering complimentary identity protection services.
Affected (this filing): 12,063
Hardin Kundla McKeon & Poletto PC reported a data breach to the Indiana Attorney General. The breach occurred on 2024-01-08 and was reported on 2025-05-29. 53 Indiana residents were affected. 12,063 individuals affected in total.
Affected (this filing): 12,063
The law firm Hardin, Kundla, McKeon, & Poletto, P.C. experienced an external system breach on January 9, 2024. The breach was discovered on March 31, 2025, and affected 12,063 individuals, including 8 residents of Maine. The firm provided written notification to the affected Maine residents on May 29, 2025, and offered 12 months of identity protection services through Cyberscout.
Affected (this filing): 8
Hardin, Kundla, McKeon & Poletto P.C. notified the NH Attorney General of a data security incident occurring in January 2024. Unauthorized acquisition of personal information (PII) occurred. 9 NH residents were notified on May 29, 2025. No evidence of misuse found. Independent cybersecurity experts were engaged.
Affected (this filing): 9
Hardin, Kundla, McKeon, & Poletto, P.C. based in Springfield, New Jersey, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-03-31 and reported on 2025-05-30. 355 Texas residents were affected. 12,063 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via U.S. Mail.
Affected (this filing): 355