MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Harvey
bd_0e1846786188d794 · schema v1 · pii pii-v1
Full breach record for Harvey →Harvey & Martin, PLLC, an accounting firm, reported a ransomware event on November 27, 2025, which encrypted files. In February 2026, IRS e-file rejections triggered an investigation revealing data exfiltration. The breach affected 24 New Hampshire residents, exposing names, SSNs, and bank account numbers. The firm restored data from backups, engaged cybersecurity experts, reset passwords, implemented MFA, and provided 24 months of credit monitoring to affected individuals. The incident was contained, and no ransom was paid.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed24 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/harvey-martin-20260708.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 8, 2026
- Raw hash
- 12af37135de0e85d2ff0c2be5763f1fb3374d8ba07060f0994bd5ce02bb279fa
Reporting entity
- Name
- Harveynorm: harvey
- Domain
- harvey.ai
Victim entity
- Name
- Harveynorm: harvey
- Domain
- harvey.ai
Incident
- Discovered
- Feb 1, 2026
- Materiality determined
- —
- Notification sent
- Jul 6, 2026
- Affected individuals
- 24
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Contacted IRS and worked with its anti-fraud program
Compliance
- Time to disclose
- 22 weeks(157 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.