HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
North Atlantic States Carpenters Benefit Funds
bd_26ca88c6d91bab3e · schema v1 · pii pii-v1
Full breach record for North Atlantic States Carpenters Benefit Funds →North Atlantic States Carpenters Benefit Funds (NASCBF) notified the New Hampshire Attorney General on February 11, 2026, of a data event affecting 7,444 NH residents. On August 18, 2025, an unauthorized actor accessed systems at the Hamden, CT office. Affected data included names, SSNs, taxpayer IDs, and financial account numbers. NASCBF reset passwords, engaged forensic specialists, notified law enforcement, and provided 12 months of credit monitoring via Epiq. No funds were stolen.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_7d0152cd19d54aa8Maine State AGfiled 2026-02-11Candidate
- bd_aa7d90f26edd4702Indiana State AGfiled 2026-02-11Verified by operator
- bd_ef203187ce86e64fVermont State AGfiled 2026-02-11Verified
- bd_823e1bfd6c35b5bfTexas State AGfiled 2026-02-13(2d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/north-atlantic-states-carpenters-benefit-funds-20260211.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 11, 2026
- Raw hash
- 52f31bef829d0ff4c7a97b76da353d0af21b185c710f151b2a078dfd700b773d
Reporting entity
- Name
- North Atlantic States Carpenters Benefit Fundsnorm: north atlantic states carpenters benefit funds
- Domain
- carpentersfund.org
Victim entity
- Name
- North Atlantic States Carpenters Benefit Fundsnorm: north atlantic states carpenters benefit funds
- Domain
- carpentersfund.org
Incident
- Discovered
- Aug 18, 2025
- Materiality determined
- —
- Notification sent
- Feb 11, 2026
- Affected individuals
- 7,444
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notifying the U.S. Department of Health and Human Services and prominent media pursuant to the Health Insurance Portability and Accountability Act (HIPAA)providing written notice of this incident to relevant state and federal regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 25 weeks(177 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.