Social EngineeringPhishingStolen CredentialsTargetedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPIIMediumContained
Williams Hart & Boundas LLP
bd_21d84c8d5f9d1cae · schema v1 · pii pii-v1
Full breach record for Williams Hart & Boundas LLP →Williams Hart & Boundas LLP notified the NH AG of a business email compromise. On June 30, 2025, the firm discovered a phishing email led to unauthorized access to a firm email account. The incident affected personal information (names, addresses, SSNs, driver's licenses, financial account numbers, health info) of approximately 13 New Hampshire residents. Notifications were sent on September 19, 2025, including credit monitoring services.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_8aca3b6fa35c5edbMaine State AGfiled 2025-10-09Verified
- bd_be1ce8a3e21067c7Vermont State AGfiled 2025-10-13(4d gap)Verified
- bd_6e5425fc35eec9ccTexas State AGfiled 2025-09-22(17d gap)Verified
- bd_387dcfeb85167badMontana State AGfiled 2025-09-19(20d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 20d gap
- bd_ae49906292b990c4Indiana State AGfiled 2025-09-19(20d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/williams-hart-boundas-20251009.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 9, 2025
- Raw hash
- 61b6ee46c7c97960a146dceeeb11f201ce68b226fd7b627c278a683afe04a290
Reporting entity
- Name
- Williams Hart & Boundas LLPnorm: williams hart boundas
Victim entity
- Name
- Williams Hart & Boundas LLPnorm: williams hart boundas
Incident
- Discovered
- Jun 30, 2025
- Materiality determined
- —
- Notification sent
- Sep 19, 2025
- Affected individuals
- 13
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- phishing_link
Compliance
- Time to disclose
- 14 weeks(101 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.