MalwareRansomwareBian LianData ExfiltratedData EncryptedCustomer Data InvolvedRansom DemandedTargetedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
Northeast Spine and Sports Medicine's
bd_0ab395dba0bb9eb0 · schema v1 · pii pii-v1
Full breach record for Northeast Spine and Sports Medicine's →Northeast Spine and Sports Medicine, LLC reported a ransomware incident attributed to the Bian Lian cyber organization. The intrusion occurred between late December 2023 and early January 2024, with detection on January 8, 2024. Approximately 3 New Hampshire residents were affected. Compromised data included PHI, SSNs, names, DOBs, and financial/insurance information. The company engaged forensic investigators, isolated systems, notified law enforcement, and implemented enhanced security measures including MFA and firewall upgrades.
Leak gap clock✗ Leak >180d41 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
A leak claim by bianlian about this victim predates this filing by 276 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_1792772f2ef0f26eLeak Sitebianlianfiled 2024-01-15(277d gap)Candidate
Regulatory filings (1) · sorted by filing gap
- bd_1b47b2bf01cc6441Maine State AGfiled 2024-10-23(5d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/northeast-spine-sports-medicine-20241018.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 18, 2024
- Raw hash
- 7287c331b2b6813480c57de27c7b9ade64070debb824490651bac3bd305bce07
Reporting entity
- Name
- Northeast Spine and Sports Medicine'snorm: northeast spine and sports medicine s
- Domain
- northeastspineandsports.com
Victim entity
- Name
- Northeast Spine and Sports Medicine'snorm: northeast spine and sports medicine s
- Domain
- northeastspineandsports.com
Incident
- Discovered
- Jan 8, 2024
- Materiality determined
- —
- Notification sent
- Oct 18, 2024
- Affected individuals
- 3
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access· Bian Lian
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- Bian LianExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection & Antitrust Bureau
Compliance
- Time to disclose
- 41 weeks(284 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.