Chiesi USA, Inc.
bd_10b714aa1a2aa745 · schema v1 · pii pii-v1
Full breach record for Chiesi USA, Inc. →Chiesi USA Inc. reported a data breach to the New Hampshire Attorney General on December 22, 2025. The company detected unauthorized access to its U.S. systems on August 28, 2025. The incident affected approximately 1,835 individuals, including 9 New Hampshire residents. Personal information accessed included names, SSNs, driver's license numbers, passport numbers, medical information, financial account information, and usernames/passwords. Chiesi engaged third-party cybersecurity specialists, secured its environment, and is providing 24 months of credit monitoring through Experian.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_30e0baca8a783e6aMaine State AGfiled 2025-12-22Candidate
- bd_e7cc2b535ec68130Vermont State AGfiled 2025-12-22Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/chiesi-usa-20251222.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2025
- Raw hash
- 93b58a8701590acb6169fc2fc39d8d694e1435b021729abb1888000cbc4cb748
Reporting entity
- Name
- Chiesi USA, Inc.norm: chiesi usa
Victim entity
- Name
- Chiesi USA, Inc.norm: chiesi usa
Incident
- Discovered
- Aug 28, 2025
- Materiality determined
- —
- Notification sent
- Dec 22, 2025
- Affected individuals
- 1,835
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.