DisclosureLens
HackingTechnologyInformationData ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDMediumContained

Arrowhead Regional Computing Consortium

bd_41134782d8d036d9 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 6, 2023

Filed

Jan 17, 2024

To disclose

49 weeks

Affected

25state residents only

Linked

4 filings

Confidence

66%
Full breach record for Arrowhead Regional Computing Consortium2 incidents on file

Arrowhead Regional Computing Consortium (ARCC) notified the New Hampshire Attorney General of unauthorized network access detected on February 6, 2023. Forensic investigation confirmed on December 7, 2023, that personal information of approximately 25 NH residents was acquired. ARCC notified affected individuals on January 11, 2024, offering one year of identity theft protection services. Data included names and government IDs. No identity theft reported.

Incident timeline

discovery → filing · 49 weeks / 345 days

Feb 6, 2023

Begins

Feb 6, 2023

Discovered

Jan 17, 2024

Filed

vs. sector median

+31 wks slower

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Indiana State AGJan 11 · first
Vermont State AGJan 11 · first
Maine State AGJan 11 · first
New Hampshire State AG+6d · this page

Pattern: first filing Jan 11 (IN), last Jan 17 (NH) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.