Confirmed breach. Intrusion Apr 5, 2025–Apr 22, 2025, discovered Apr 22, 2025 — the first regulatory filing landed 157 days later (flagged late). 5 individuals reported across the linked filings.
Sciarabba Walker & Co., LLP notified the NH AG of unauthorized access to two employee email accounts between April 5 and April 22, 2025. The actor accessed names and SSNs of 2 NH residents. Discovery was April 22, 2025. Notifications sent September 26, 2025. Response included credential resets, forensic investigation, and 12-month credit monitoring.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Sciarabba Walker & Co., LLP reported a data breach to the Maine Attorney General, which was discovered on April 22, 2025. The breach, which occurred on April 5, 2025, affected 3 Maine residents. The company provided written notification to affected individuals on September 26, 2025, and offered 12 months of credit monitoring and identity theft protection services through Epiq. The specific nature of the breach was not detailed.
Affected (this filing): 3
ME AG >90d · 157dME resident >60d · 157d
🍁Vermont State AGlinked via multistate filing link · 100%
Sciarabba Walker & Co., LLP notified consumers of unauthorized access to two employee email accounts between April 5 and April 22, 2025. The incident involved the compromise of email credentials, leading to the exposure of names and other personal data. The firm engaged third-party cybersecurity specialists, secured the email environment, and is offering credit monitoring services to affected individuals.