HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
NFI North
bd_1196ad8fd7fe17cb · schema v1 · pii pii-v1
Full breach record for NFI North →NFI North reported a cybersecurity incident to the New Hampshire Attorney General on November 13, 2025. An unauthorized third party accessed the network environment on or about September 6, 2025. The incident affected 72 New Hampshire residents, compromising names and Social Security numbers. NFI North engaged forensic specialists, notified the FBI, rebuilt systems, and provided 12 months of credit monitoring to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_58691ec86d23b789Maine State AGfiled 2025-11-13Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/nfi-north-20251113.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 3a9b4ef022fe9058d2cace0e5d68f2de071f29c3bbcfd396debf4eac61a0c900
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- NFI Northnorm: nfi north
Incident
- Discovered
- Sep 6, 2025
- Materiality determined
- —
- Notification sent
- Nov 13, 2025
- Affected individuals
- 72
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the FBI and is fully cooperating with their investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(68 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.