Davies, McFarland & Carroll.
Clustered 4 filings across 4 jurisdictions · filing window Jun 4, 2025 → Dec 1, 2025. View entity profile → Other incidents for this victim →
incident inc_fb9c71d639f340be · merge_method human · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Gap between first leak claim and first regulatory filing
Time between earliest and latest filing
Not recorded for this incident
Materiality delta · SEC filing delay — no SEC 8-K in this cluster.
PHI
FEDERAL ME NH
Leak Site · HHS OCR · State AG
Earliest sighting first · deep chronology in Litigation Timeline
May 19, 2025
When the intrusion reportedly occurred, per the linked filings
May 22, 2025
Reported by MAINE AG, NEW HAMPSHIRE AG filings
Davies, McFarland & Carroll.
Jun 5, 2025
Reported by Leak Site filing
HHS OCR breach portal entry: Davies, McFarland & Carroll LLC (PA), a Business Associate, reported a Hacking/IT Incident affecting a Network Server on 2025-11-24. Reported individuals affected: 54,712. No narrative description was provided in the portal row; specifics of the intrusion vector, threat actor, and data types beyond PHI are not disclosed in this source.
Davies, McFarland & Carroll LLC reported an external system breach (hacking) occurring on May 19, 2025, discovered on May 22, 2025. The incident affected 54,712 individuals, including 4 Maine residents. Personal information, including names and government identifiers, was compromised. The firm notified affected individuals electronically on November 24, 2025, and offered TransUnion Cyberscout identity theft protection services.
Affected (this filing):
Davies, McFarland & Carroll LLC (DMC), a law firm, notified the New Hampshire Attorney General of a cybersecurity incident affecting approximately 6 NH residents. Unauthorized access to DMC's internal network occurred between May 19-22, 2025. Personal information potentially accessed included names, DOBs, driver's licenses, financial account numbers, and SSNs. DMC engaged cybersecurity experts, contained the breach, and provided 12 months of credit monitoring to affected individuals. Notification letters were sent on November 24, 2025.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Affected (this filing): 54,712
Affected (this filing): 6