HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
InvoiceCloud
bd_41688672135d043c · schema v1 · pii pii-v1
Full breach record for InvoiceCloud →InvoiceCloud, Inc. notified the New Hampshire AG of a security event on July 16, 2025. On June 16, 2025, unauthorized code was placed on systems supporting customer payment websites. Approximately 20 NH residents had name, billing address, email, payment card number, expiration date, and CVV scraped. InvoiceCloud engaged forensic investigators, notified law enforcement, removed the script, and offered 1 year of credit monitoring via TransUnion.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed20 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/invoicecloud-20250716.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 16, 2025
- Raw hash
- 882cf5fc0f825bb62f2c522db370088c431a4849b75caf85f7cbf4ac286cd79d
Reporting entity
- Name
- InvoiceCloudnorm: invoicecloud
- Domain
- invoicecloudservice.com
Victim entity
- Name
- InvoiceCloudnorm: invoicecloud
- Domain
- invoicecloudservice.com
Incident
- Discovered
- Jun 16, 2025
- Materiality determined
- —
- Notification sent
- Jul 16, 2025
- Affected individuals
- 20
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.