HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
David Yurman
bd_2154d2fd94c6e52c · schema v1 · pii pii-v1
Full breach record for David Yurman →David Yurman Enterprises LLC notified the NH Attorney General of a data security incident involving a previously unknown vulnerability (zero-day) in Oracle E-Business Suite. Unauthorized access occurred between August 9-12, 2025. The breach affected the names and Social Security numbers of one New Hampshire resident (a current or former contractor). David Yurman secured the environment by applying an Oracle patch and offered complimentary identity protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/david-yurman-20251112.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 12, 2025
- Raw hash
- 5d3ca10ba11be5e3ef767dd64b5b0c98d500cbb5bcbbfe78da5c807fad30f54d
Reporting entity
- Name
- David Yurmannorm: david yurman
- Domain
- davidyurman.com
Victim entity
- Name
- David Yurmannorm: david yurman
- Domain
- davidyurman.com
Incident
- Discovered
- Sep 29, 2025
- Materiality determined
- —
- Notification sent
- Nov 12, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.