MalwareRansomwareStolen CredentialsQilinData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedMulti-Stage ChainIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICPIIMediumContained
Daniels Law Group LLC
bd_1136f26dc1e53970 · schema v1 · pii pii-v1
Full breach record for Daniels Law Group LLC →Daniels Law Group, LLC reported a ransomware incident to the New Hampshire AG on August 12, 2025. A threat actor associated with the Qilin ransomware group gained access via stolen MSP credentials around June 26, 2025, encrypting data on July 1, 2025. Exfiltration was suspected on July 9, 2025. One NH resident's PII (SSN, DL, health info) was affected. The firm engaged forensics, notified law enforcement, and offered credit monitoring.
Leak gap clock⏱ Leak >30d5 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
A leak claim by qilin about this victim predates this filing by 34 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_8c44d65e9958589dLeak Siteqilinfiled 2025-07-21(22d gap)Verified
- bd_f0477ba0758f0f54Leak Siteqilinfiled 2025-07-09(34d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_063312025bf467d8Maine State AGfiled 2025-08-12Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/daniels-law-group-20250812.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 12, 2025
- Raw hash
- e94d451edfd806101fb5d245eeb2c31a52a14c26eb9657fb5622cf74625edbe8
Reporting entity
- Name
- Daniels Law Group LLCnorm: daniels law
- Domain
- danielslawgroupllc.com
Victim entity
- Name
- Daniels Law Group LLCnorm: daniels law
- Domain
- danielslawgroupllc.com
Incident
- Discovered
- Jul 9, 2025
- Materiality determined
- —
- Notification sent
- Aug 12, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICPII
- Attack vector
- Ransomware· Qilin
- MITRE ATT&CK
- T1078 Valid AccountsT1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- QilinExternalFinancial
- Regulator citations
- notify local and federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.