HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedPIIPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Carleton-Willard Village
bd_3a0783a1a7b5466b · schema v1 · pii pii-v1
Full breach record for Carleton-Willard Village →Carleton Willard Homes Inc. notified the NH AG that unauthorized access to two employee email accounts occurred between Dec 19, 2024 and Mar 13, 2025. Forensic review on May 16, 2025 confirmed potential unauthorized access to files containing PHI, SSNs, and PII of 1 NH resident. Credit monitoring offered.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/carleton-willard-homes-20250623.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 23, 2025
- Raw hash
- 78d5554cef50736799aa550d05166e70d557eb27b31f69da2c925579829c001a
Reporting entity
- Name
- Carleton-Willard Villagenorm: carleton willard village
- Domain
- cwvillage.org
Victim entity
- Name
- Carleton-Willard Villagenorm: carleton willard village
- Domain
- cwvillage.org
Incident
- Discovered
- Mar 13, 2025
- Materiality determined
- May 16, 2025
- Notification sent
- Jun 17, 2025
- Affected individuals
- 1
- Data types
- PIIPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 weeks(102 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.