HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumActive
LABELLA ASSOCIATES, D.P.C.
bd_27a5d1c68870f4d0 · schema v1 · pii pii-v1
Full breach record for LABELLA ASSOCIATES, D.P.C. →LaBella Associates notified the New Hampshire Attorney General of a cybersecurity incident discovered on March 24, 2025. The breach potentially exposed the names, Social Security numbers, driver's license numbers, passport numbers, and financial account numbers of 11 New Hampshire residents. LaBella engaged forensic investigators and an eDiscovery team, secured its systems, and began notifying affected individuals on November 12, 2025, offering 12 months of credit monitoring.
Leak gap clock✗ Leak >180d33 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by rhysida about this victim predates this filing by 197 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_03cfa8083a54f524Indiana State AGfiled 2025-11-12Verified
- bd_4a04fdd952307ee3Montana State AGfiled 2025-11-12Candidate
- bd_5ab4b9ccf4fd98b8Vermont State AGfiled 2025-10-12(31d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/labella-20251112.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 12, 2025
- Raw hash
- a20e3bcdb9b968d0376624497e70ea9bc0c9772cd93374105560e5a73aec868c
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- LABELLA ASSOCIATES, D.P.C.norm: labella associates dpc
- Domain
- labellapc.com
Incident
- Discovered
- Mar 24, 2025
- Materiality determined
- —
- Notification sent
- Nov 12, 2025
- Affected individuals
- 11
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 33 weeks(233 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.