MalwareRansomwareData EncryptedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
AOS, Inc.
bd_28b8aaa996882905 · schema v1 · pii pii-v1
Full breach record for AOS, Inc. →AOS, Inc. reported a ransomware incident to the New Hampshire Attorney General on September 12, 2025. The breach occurred on July 31, 2025, when an unauthorized third party exploited a third-party software vulnerability to access AOS systems and encrypt files. The incident affected 148 New Hampshire residents, exposing names, addresses, SSNs, driver's license numbers, passport numbers, and financial account information. AOS engaged forensic investigators, notified law enforcement, and offered 12 months of credit monitoring to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_8fb6953d89670c6aCalifornia State AGfiled 2025-09-12Verified
- bd_9c9072871f710a25Montana State AGfiled 2025-09-12Verified
- bd_cf3162f9914d2431Indiana State AGfiled 2025-09-12Verified
- bd_2891c165eb79b667Texas State AGfiled 2025-09-15(3d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/aos-20250912.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 12, 2025
- Raw hash
- 5ec99db27d39d93000ae4450d7c9d422532dcc57db71367b5ac46d5d53b966a6
Reporting entity
- Name
- AOS, Inc.norm: aos
Victim entity
- Name
- AOS, Inc.norm: aos
Incident
- Discovered
- Jul 31, 2025
- Materiality determined
- —
- Notification sent
- Sep 12, 2025
- Affected individuals
- 148
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(43 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.