HackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
HENNESSY ADVISORS, INC.
bd_072c9ab8534cfc81 · schema v1 · pii pii-v1
Full breach record for HENNESSY ADVISORS, INC. →Hennessy Advisors, Inc. disclosed a data security incident discovered on March 30, 2025, involving unauthorized access and release of personal information for certain investors in the Hennessy Funds. The company retained third-party specialists to investigate and secure systems. Personal information potentially affected includes identity and financial data. Complimentary credit monitoring and identity theft protection services are being offered to affected individuals.
California clockDiscovered Mar 30, 2025 → Notified Feb 23, 2026330d ✗ CA 60-day late47 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_41991ab4574f8c98Maine State AGfiled 2026-02-24Verified by operator
- bd_6d4e4e25f72021c3New Hampshire State AGfiled 2026-02-24Verified
- bd_4a3d6923a18d23b5Texas State AGfiled 2026-02-25(1d gap)Verified by operator
- bd_155d62cf97956468Indiana State AGfiled 2026-02-23(1d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_d11bdc8476440748Vermont State AGfiled 2026-02-23(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-619204
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 24, 2026
- Raw hash
- b5111f847fe7ced0e1c25438521d7b17bccfe9638714231b7cd0c4d276ef0c5c
Reporting entity
- Name
- HENNESSY ADVISORS, INC.norm: hennessy advisors
- Domain
- hennessyadvisors.com
Victim entity
- Name
- HENNESSY ADVISORS, INC.norm: hennessy advisors
- Domain
- hennessyadvisors.com
Incident
- Discovered
- Mar 30, 2025
- Materiality determined
- —
- Notification sent
- Feb 23, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Filed notification with California Attorney General
Compliance
- Time to disclose
- 47 weeks(331 days from discovery to filing)
- Compliance flags
- CA 60-day late · 330dCA AG copy ≤15d · 1d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 30, 2025→ Notified: Feb 23, 2026330d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Feb 23, 2026→ AG copy submitted: Feb 24, 20261d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.