Richmond Behavioral Health Authority
bd_38e8c8a165ef2012 · schema v1 · pii pii-v1
Full breach record for Richmond Behavioral Health Authority →Richmond Behavioral Health Authority (RBHA) notified the New Hampshire Attorney General on December 9, 2025, of a ransomware incident. Malicious actors accessed RBHA's network on or about September 29, 2025, and deployed ransomware on September 30, 2025. A limited set of data, including names, SSNs, passport numbers, financial account info, and health information, was potentially accessed. Approximately 4 New Hampshire residents are estimated to be affected. RBHA engaged forensic experts, notified law enforcement, terminated access, and provided Kroll identity monitoring services.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3fce0541fd942e3cMontana State AGfiled 2025-12-09(7d gap)Candidate
- bd_e98cc50507d66314Indiana State AGfiled 2025-12-04(12d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/richmond-behavioral-health-authority-20251216.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 16, 2025
- Raw hash
- 5719ab1f53c297547f8e82f7b44de7edd678d3adb71b8ccadb4f5dc9e9f54324
Reporting entity
- Name
- Richmond Behavioral Health Authoritynorm: richmond behavioral health authority
- Domain
- rbha.org
Victim entity
- Name
- Richmond Behavioral Health Authoritynorm: richmond behavioral health authority
- Domain
- rbha.org
Incident
- Discovered
- Sep 30, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Office of the Attorney General of New Hampshire
Compliance
- Time to disclose
- 11 weeks(77 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.