HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Service Lighting & Electrical Supplies, Inc.
bd_3b90264d81e98a0e · schema v1 · pii pii-v1
Full breach record for Service Lighting & Electrical Supplies, Inc. →Service Lighting, Inc. notified the New Hampshire Attorney General of a cybersecurity incident involving its e-commerce website. Malicious code was installed to capture payment card data (names, card numbers, expiration, CVV) for transactions between March 12, 2025, and September 16, 2025. Approximately 150 New Hampshire residents were affected. Notifications were sent on March 4, 2026. No identity fraud has been reported to date.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_d7188306de15b978Texas State AGfiled 2026-03-06(3d gap)Verified by operator
- bd_39f9a73ca21d9034Maine State AGfiled 2026-03-05(4d gap)Verified by operator
- bd_629f45567b9be856Oregon State AGfiled 2026-03-05(4d gap)Verified by operator
- bd_02734fad6e236147Indiana State AGfiled 2026-03-04(5d gap)Candidate
Show 3 more filings ↓Show fewer ↑up to 5d gap
- bd_8631ed68eab105d4California State AGfiled 2026-03-04(5d gap)Verified by operator
- bd_993241b084805503Indiana State AGfiled 2026-03-04(5d gap)Candidate
- bd_b7103c1db064e70fVermont State AGfiled 2026-03-04(5d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/service-lighting-20260309.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 9, 2026
- Raw hash
- e8b67af428c3c4b2190bb11de8aafd5cb8cf888cf3b0cf0e2ac41e21c2f3de26
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- Service Lighting & Electrical Supplies, Inc.norm: service lighting electrical supplies
Incident
- Discovered
- Sep 16, 2025
- Materiality determined
- —
- Notification sent
- Mar 4, 2026
- Affected individuals
- 150
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 weeks(174 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.