HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Hudson River Partners I L.P.
bd_21fe280fdcbdc5b0 · schema v1 · pii pii-v1
Full breach record for Hudson River Partners I L.P. →The Thayer Hotel (dba Hudson River Partners I L.P.) notified the New Hampshire Attorney General of a data security incident on November 5, 2025. Unauthorized access occurred on September 19, 2025, exposing personal information of 174 New Hampshire residents, including driver's license numbers, passport numbers, and dates of birth. The hotel engaged third-party forensic experts and Kroll Security for credit monitoring.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_d48218c6d02db346Texas State AGfiled 2025-11-04(1d gap)Verified
- bd_12aa427de683d475California State AGfiled 2025-11-03(2d gap)Verified
- bd_5ff7442183fae9c4Indiana State AGfiled 2025-11-03(2d gap)Verified
- bd_7e2139f3f98129d0Maine State AGfiled 2025-11-03(2d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 5d gap
- bd_fed038a81b8b76acVermont State AGfiled 2025-11-03(2d gap)Verified
- bd_8009cd56be9477b8Montana State AGfiled 2025-10-31(5d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/hudson-river-partners-thayer-hotel-20251105.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 5, 2025
- Raw hash
- 5350dedb42e752fb0d6c024d3652c54e7ff77aeaecbe472ffa0f5f9ade766b09
Reporting entity
- Name
- Hudson River Partners I L.P.norm: hudson river partners i
- Domain
- thethayerhotel.com
Victim entity
- Name
- Hudson River Partners I L.P.norm: hudson river partners i
- Domain
- thethayerhotel.com
Incident
- Discovered
- Sep 19, 2025
- Materiality determined
- —
- Notification sent
- Oct 31, 2025
- Affected individuals
- 174
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(47 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.