MalwareRansomwareData ExfiltratedData EncryptedData PublishedRansom DemandedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Box Elder County
bd_2a7063a4068a187a · schema v1 · pii pii-v1
Full breach record for Box Elder County →Box Elder County, Utah, notified the New Hampshire Attorney General of a ransomware incident affecting two New Hampshire residents. Unauthorized access occurred between May 6, 2025, and August 3, 2025. The County detected ransomware on August 3, 2025, and engaged forensic consultants. Personal information, including names and Social Security numbers, was exfiltrated and posted online. The County refused to pay the ransom. Notification to affected individuals was sent on December 17, 2025.
Leak gap clock⏱ Leak >90d20 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by interlock about this victim predates this filing by 133 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_2991d0849073512fMaine State AGfiled 2025-12-17(7d gap)Candidate
- bd_a1e28b49e506ea41Montana State AGfiled 2025-12-17(7d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/box-elder-county-utah-20251224.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 24, 2025
- Raw hash
- be9e5948cf7c303f5fc4e7a2c507e83ceec54b8c55286f26e08efd003c2903c1
Reporting entity
- Name
- Box Elder Countynorm: box elder county
- Domain
- boxeldercounty.org
Victim entity
- Name
- Box Elder Countynorm: box elder county
- Domain
- boxeldercounty.org
Incident
- Discovered
- Aug 3, 2025
- Materiality determined
- —
- Notification sent
- Dec 17, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 ChannelT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 20 weeks(143 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.