Clustered 4 filings across 3 jurisdictions · filing window Apr 7, 2026 → Jul 6, 2026. View entity profile → Other incidents for this victim →
incident inc_831651bacbc8498e · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Government ID · Financial account
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
ME NH VT
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Nov 17, 2025 → Mar 25, 2026
When the intrusion reportedly occurred, per the linked filings
Nov 17, 2025
Reported by VERMONT AG, NEW HAMPSHIRE AG filings
Mar 25, 2026
Reported by MAINE AG filing
JM Forbes and Co. filed a supplemental notice to the New Hampshire Attorney General regarding a business email compromise incident. An unauthorized external party gained access to an employee email account via social engineering/phishing on November 17, 2025. The incident affected 45 individuals (26 NH residents), exposing names, addresses, SSNs, and account numbers. No fraudulent transactions occurred. JMF offered 2 years of credit monitoring.
Affected (this filing):
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
J.M. Forbes & Co. notified consumers of a security incident detected on November 17, 2025, involving unauthorized access to an employee email account. The breach was part of a business email compromise attempt via social engineering. Affected data included names, addresses, Social Security numbers, and account numbers. No fraudulent transactions occurred. The company engaged forensic experts and offers two years of credit monitoring.
JM Forbes & Co., a wealth management firm, notified the New Hampshire Attorney General of a security incident affecting 19 residents. On November 17, 2025, suspicious activity was detected on an employee email account. Investigation determined unauthorized access occurred via social engineering (business email compromise). Affected data included names, addresses, SSNs, and account numbers. No fraudulent transactions occurred. JMF provided two years of credit monitoring and enhanced safeguards.
Affected (this filing): 19
JM Forbes & Co. reported a business email compromise incident involving unauthorized access to an email account via social engineering. Discovered March 25, 2026, no evidence of data misuse was found. 23 Maine residents notified with credit monitoring offers.
Affected (this filing): 23