HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Microforum Services Group
bd_36ce44b069df2ee3 · schema v1 · pii pii-v1
Full breach record for Microforum Services Group →Microforum Services Group notified the New Hampshire Attorney General of a data event occurring between December 18 and 22, 2025, discovered on December 22, 2025. The incident involved unauthorized copying of customer name, contact, and credit card information. One New Hampshire resident was affected. Microforum engaged forensic specialists, retained counsel, and provided 24 months of credit monitoring via TransUnion. Notification letters were mailed on April 21, 2026.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/microforum-services-group-20260421.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2026
- Raw hash
- f0901437f9fe46ad29907af6f30adcaa7ad1e7a3a1f1d5ecc728215e2a000db8
Reporting entity
- Name
- Wilson, Elser, Moskowitz, Edelman & Dicker LLPnorm: wilson elser moskowitz edelman dicker
Victim entity
- Name
- Microforum Services Groupnorm: microforum services
Incident
- Discovered
- Dec 22, 2025
- Materiality determined
- —
- Notification sent
- Apr 21, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 weeks(120 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.