HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Endue Software
bd_1ff35c438b26be88 · schema v1 · pii pii-v1
Full breach record for Endue Software →Endue Software, a provider of infusion care management software, notified the NH AG of a cybersecurity event on Feb 17, 2025, following unauthorized access on Feb 16, 2025. Files from internal systems were copied, affecting 67 NH residents with PII including SSNs. Endue notified law enforcement, offered credit monitoring, and is dissolving its business.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_08920fbd0889d482Indiana State AGfiled 2025-04-11Verified
- bd_15dd0c0c8fb43bf4HHS OCRfiled 2025-04-11Verified
- bd_2ba6e7caea77b873Vermont State AGfiled 2025-04-11Verified
- bd_3f9524f86d2e0052Maine State AGfiled 2025-04-11Verified
Show 3 more filings ↓Show fewer ↑
- bd_5bc86c50c5edfc76Vermont State AGfiled 2025-04-11Verified
- bd_7345eadbe357342dCalifornia State AGfiled 2025-04-11Verified
- bd_96d712f75f14a6b9Montana State AGfiled 2025-04-11Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/endue-software-20250411.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 11, 2025
- Raw hash
- ce22debdedb41ad9924863870eaa3553b93e8216127c961361d4867a8837c61b
Reporting entity
- Name
- Endue Softwarenorm: endue software
Victim entity
- Name
- Endue Softwarenorm: endue software
Incident
- Discovered
- Feb 17, 2025
- Materiality determined
- —
- Notification sent
- Apr 11, 2025
- Affected individuals
- 67
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified federal law enforcementProviding written notice to relevant state and federal regulatorsNotifying the three major credit reporting agenciesNotifying the U.S. Department of Health and Human Services
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.