MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
North Los Angeles County Regional Center
bd_147635ef84b2335f · schema v1 · pii pii-v1
Full breach record for North Los Angeles County Regional Center →North Los Angeles County Regional Center (NLACRC) notified the New Hampshire Attorney General of a ransomware incident. Unauthorized access occurred between November 20 and December 1, 2024. NLACRC discovered the activity on November 28, 2024. The attacker exfiltrated PII and PHI before encrypting systems. Two New Hampshire residents were affected. Notification to residents began June 30, 2026.
Leak gap clock✗ Leak >180d20 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 570 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_abad50be558f6b62Vermont State AGfiled 2026-06-30(6d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/north-los-angeles-county-regional-center-20260706.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 6, 2026
- Raw hash
- 47ef175b71ddab1dc20bc877d599c37b4e5aa69b5e8f68b1cacfb8f36d8b5cfd
Reporting entity
- Name
- North Los Angeles County Regional Centernorm: north los angeles county regional center
- Domain
- nlacrc.org
Victim entity
- Name
- North Los Angeles County Regional Centernorm: north los angeles county regional center
- Domain
- nlacrc.org
Incident
- Discovered
- Nov 28, 2024
- Materiality determined
- —
- Notification sent
- Jun 30, 2026
- Affected individuals
- 2
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Consumer Protection Bureau
Compliance
- Time to disclose
- 20 months(585 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.