MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
BHI Energy I Specialty Services LLC
bd_0058c059945a2749 · schema v1 · pii pii-v1
Full breach record for BHI Energy I Specialty Services LLC →BHI Energy | Specialty Services LLC notified the New Hampshire Attorney General of a ransomware incident. The threat actor gained access on May 30, 2023, exfiltrated data through June 29, 2023, and deployed ransomware. BHI discovered the encryption on June 29, 2023. The breach affected 1,282 New Hampshire residents, involving names, addresses, and government IDs. BHI isolated systems, engaged forensic investigators, reset passwords, and implemented MFA. Notices were sent on October 18, 2023.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_06d2a8db0a5a2a79Washington State AGfiled 2023-10-18Candidate
- bd_36f52a39ba8b286dCalifornia State AGfiled 2023-10-18Verified
- bd_46cdc3e8aa9e883dMontana State AGfiled 2023-10-18Verified
- bd_56c902fa1f6b5407Oregon State AGfiled 2023-10-18Verified
Show 2 more filings ↓Show fewer ↑
- bd_6b70bd566e3b8be6Vermont State AGfiled 2023-10-18Verified
- bd_8fa2440398ccf349Maine State AGfiled 2023-10-18Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/bhi-energy-specialty-services-20231018.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 18, 2023
- Raw hash
- deb6c416631ed8d553decea37469326508e50e927f73499edc9a512ea4b68a3f
Reporting entity
- Name
- BHI Energy I Specialty Services LLCnorm: bhi energy i specialty
Victim entity
- Name
- BHI Energy I Specialty Services LLCnorm: bhi energy i specialty
Incident
- Discovered
- Jun 29, 2023
- Materiality determined
- —
- Notification sent
- Oct 18, 2023
- Affected individuals
- 1,282
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Consumer Protection Bureau, Office of the New Hampshire Attorney General
Compliance
- Time to disclose
- 16 weeks(111 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.