The Maine Office of the Attorney General disclosed a data breach at Gershman Investment Corp. that transpired between September 7 and 22, 2021, compromising the personal information of 52,737 individuals, including five Maine residents. The incident stemmed from an external system breach caused by hacking, granting unauthorized access to highly sensitive data. Exposed information included names, Social Security Numbers (SSNs), driver’s license/passport numbers, and financial account details critical identifiers that heighten risks of identity theft, financial fraud, and long-term reputational harm for affected individuals. The breach’s scale and the nature of the stolen data particularly SSNs and financial records suggest severe operational and compliance repercussions for the company. Such exposures often trigger regulatory scrutiny (e.g., under state breach notification laws or federal frameworks like GLBA), potential litigation, and erosion of customer trust. The involvement of external hackers further implies a targeted cyber attack, distinguishing this from accidental vulnerabilities or internal negligence. Mitigation efforts likely involved forensic investigations, credit monitoring for victims, and systemic security overhauls to prevent recurrence, though the article does not specify these measures.
TPRM report: https://www.rankiteo.com/company/gershman-investment-corp
"id": "ger807082025",
"linkid": "gershman-investment-corp",
"type": "Cyber Attack",
"date": "6/2021",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 52737,
'industry': 'Investment/Financial Services',
'name': 'Gershman Investment Corp.',
'type': 'Corporation'}],
'attack_vector': 'Hacking (External System Breach)',
'data_breach': {'data_exfiltration': 'Yes (unauthorized access)',
'number_of_records_exposed': 52737,
'personally_identifiable_information': ['Names',
'Social Security '
'Numbers',
'Driver’s License '
'Numbers',
'Passport Numbers'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Financial Data']},
'date_publicly_disclosed': '2022-05-13',
'description': 'The Maine Office of the Attorney General reported a data '
'breach at Gershman Investment Corp. involving unauthorized '
'access to personal information, including names, Social '
'Security Numbers, driver’s license/passport numbers, and '
'financial account numbers, due to an external system breach '
'caused by hacking.',
'impact': {'data_compromised': ['Names',
'Social Security Numbers',
'Driver’s License Numbers',
'Passport Numbers',
'Financial Account Numbers'],
'identity_theft_risk': 'High (PII exposed)',
'payment_information_risk': 'High (Financial account numbers '
'exposed)'},
'post_incident_analysis': {'root_causes': 'External system breach due to '
'hacking'},
'references': [{'date_accessed': '2022-05-13',
'source': 'Maine Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': 'Maine Office of the '
'Attorney General'},
'response': {'communication_strategy': 'Public disclosure via Maine Office of '
'the Attorney General'},
'title': 'Data Breach at Gershman Investment Corp.',
'type': 'Data Breach'}