HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
The May Institute, Inc.
bd_266c7d36ba41aac3 · schema v1 · pii pii-v1
Full breach record for The May Institute, Inc. →The May Institute, Inc. notified 136 New Hampshire residents of a cybersecurity incident discovered on December 14, 2023, involving unauthorized access to network files starting December 5, 2023. The breach potentially exposed personal information, including government identifiers. The Institute engaged federal law enforcement, notified HHS, and provided credit monitoring services through IDX to affected individuals.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_741bdbdf65f0748bIndiana State AGfiled 2024-04-01Verified
- bd_b84a1b378974faf3Vermont State AGfiled 2024-04-01Verified
- bd_c36bf0a5f4471980Maine State AGfiled 2024-04-01Candidate
- bd_137142407e3cac51Maine State AGfiled 2024-05-07(36d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 36d gap
- bd_24be293e36e71d44Vermont State AGfiled 2024-05-07(36d gap)Verified
- bd_5207e8054ff815efNew Hampshire State AGfiled 2024-05-07(36d gap)Verified
- bd_d04a26b2741bc21cCalifornia State AGfiled 2024-05-07(36d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/may-institute-20240401.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 1, 2024
- Raw hash
- f1967cc323f196b3de1521cf92e581e1a1c2c77d6895cbda295caa6ec78a5f68
Reporting entity
- Name
- The May Institute, Inc.norm: the may institute
Victim entity
- Name
- The May Institute, Inc.norm: the may institute
Incident
- Discovered
- Dec 14, 2023
- Materiality determined
- —
- Notification sent
- Apr 1, 2024
- Affected individuals
- 136
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified federal law enforcement regarding the incidentproviding written notice of this incident to the consumer reporting agencies and to the relevant state regulatorsnotified the U.S. Department of Health and Human Services
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 weeks(109 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.