HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Oldman Sallus & Gold LLP
bd_3c2ea149c926b80e · schema v1 · pii pii-v1
Full breach record for Oldman Sallus & Gold LLP →Oldman Sallus & Gold LLP notified the NH AG of a data event where an unauthorized actor accessed an employee email account between Jan 12 and Apr 16, 2024. Suspicious activity was detected in Aug 2024. One NH resident's name and SSN were potentially exposed. OSG provided 12 months of credit monitoring and implemented additional security measures.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/oldman-sallus-gold-20250609.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 9, 2025
- Raw hash
- 68a3891d135d054ddee960af7ac447be26829f387260280ac1ce0e82523abc23
Reporting entity
- Name
- Oldman Sallus & Gold LLPnorm: oldman sallus gold
Victim entity
- Name
- Oldman Sallus & Gold LLPnorm: oldman sallus gold
Incident
- Discovered
- Aug 1, 2024
- Materiality determined
- Apr 8, 2025
- Notification sent
- Jun 10, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- providing written notice of the Event to relevant state regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 45 weeks(312 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.