HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
DocketWise
bd_19d49447e198e5e8 · schema v1 · pii pii-v1
Full breach record for DocketWise →DocketWise, a case management platform for immigration attorneys, notified the New Hampshire Attorney General of a data security incident in October 2025. Unauthorized actors used valid credentials to access a third-party partner instance and clone repositories containing customer data. The incident affected 15 New Hampshire residents, exposing names, addresses, SSNs, and government IDs. DocketWise engaged forensic experts, notified the FBI, and provided 24 months of credit monitoring.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_14c2b0dfc72d503eWashington State AGfiled 2026-04-03Candidate
- bd_270698bf44ac9aafMaine State AGfiled 2026-04-03Verified
- bd_db21719c17d2f149Vermont State AGfiled 2026-04-03Verified
- bd_e285f2bea7e3adc5Indiana State AGfiled 2026-04-03Verified by operator
Show 4 more filings ↓Show fewer ↑up to 49d gap
- bd_f56df3950ca029eeCalifornia State AGfiled 2026-04-03Verified by operator
- bd_40e1c71041a9a978New Hampshire State AGfiled 2026-05-01(28d gap)Verified
- bd_b7206884fd165144California State AGfiled 2026-05-01(28d gap)Verified by operator
- bd_1f933422ef9106ceMaine State AGfiled 2026-05-22(49d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/docketwise-20260403.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 3, 2026
- Raw hash
- 7678fd9a4d4b08c5e4a73f9c7e4ce4fc370ad599f00851cd0844fa89c476aa8b
Reporting entity
- Name
- GOODWIN PROCTER LLPnorm: goodwin procter
- Domain
- goodwinlaw.com
Victim entity
- Name
- DocketWisenorm: docketwise
- Domain
- app.docketwise.com
Incident
- Discovered
- Oct 1, 2025
- Materiality determined
- —
- Notification sent
- Apr 3, 2026
- Affected individuals
- 15
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation (“FBI”)
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 weeks(184 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.