HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
CPAP Medical Supplies and Services Inc.
bd_18cda33dcc3d3a6b · schema v1 · pii pii-v1
Full breach record for CPAP Medical Supplies and Services Inc. →CPAP Medical Supplies and Services Inc. notified the New Hampshire Attorney General of a cybersecurity incident affecting 154 NH residents. Unauthorized access occurred between Dec 13-21, 2024; discovered June 27, 2025. Compromised data included names, SSNs, driver's licenses, bank account/routing numbers, and medical/health insurance info. CPAP engaged forensic investigators, contained the threat, and offered one year of credit monitoring to affected individuals. Notification letters were mailed August 15, 2025.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_642d21260c1396abWashington State AGfiled 2025-08-15(7d gap)Candidate
- bd_8471a86266d610a4California State AGfiled 2025-08-15(7d gap)Candidate
- bd_d9a55ac561995bedHHS OCRfiled 2025-08-15(7d gap)Verified
- bd_f5bd2c1d7a6206baMaine State AGfiled 2025-08-15(7d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cpap-medical-supplies-services-20250822.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 22, 2025
- Raw hash
- c1e47c6416a45843b41dbdfc44a5b82ba3d94f5ed070e0cf7d1f36e3a3a8595f
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- CPAP Medical Supplies and Services Inc.norm: cpap medical supplies and
- Domain
- cpapmedical.com
Incident
- Discovered
- Jun 27, 2025
- Materiality determined
- —
- Notification sent
- Aug 15, 2025
- Affected individuals
- 154
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.