HackingPhishingCustomer Data InvolvedIDENTITY_BASICLowContained
Sprouse Shrader Smith PLLC
bd_03c5059d95a354fa · schema v1 · pii pii-v1
Full breach record for Sprouse Shrader Smith PLLC →Sprouse Shrader Smith PLLC filed a supplemental notice with the New Hampshire Attorney General on April 17, 2026, regarding a security incident discovered on February 25, 2025. The incident involved unauthorized access via a phishing link, resulting in the copying of limited personal information (names) from the firm's network. One New Hampshire resident was notified on April 16, 2026. The firm engaged cybersecurity specialists, disconnected systems, and provided 12-24 months of credit monitoring.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_5ccacb39f9b8310fTexas State AGfiled 2026-05-05(18d gap)Verified
- bd_b92a9f24a528a3f1New Hampshire State AGfiled 2026-03-16(32d gap)Verified
- bd_2eb301f061c7c9c1Indiana State AGfiled 2026-03-10(38d gap)Candidate
- bd_4ef7b13f8d901a9bVermont State AGfiled 2026-03-10(38d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 38d gap
- bd_5de596b35ed93fd5Maine State AGfiled 2026-03-10(38d gap)Verified
- bd_73343a817e875746Indiana State AGfiled 2026-03-10(38d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sprouse-shrader-smith-20260417.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 17, 2026
- Raw hash
- 3491f650f7b18df39a76f23d2a32d1944f2c4dfa0c5d6bf6c3b42fe27cd4cc5f
Reporting entity
- Name
- Sprouse Shrader Smith PLLCnorm: sprouse shrader smith
Victim entity
- Name
- Sprouse Shrader Smith PLLCnorm: sprouse shrader smith
Incident
- Discovered
- Feb 25, 2025
- Materiality determined
- —
- Notification sent
- Apr 16, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- notified the FBI and local law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 14 months(416 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.