MalwareRansomwareCapture Stored DataData ExfiltratedData EncryptedCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
Bay Bridge Administrators
bd_41fc712ff0e60b1f · schema v1 · pii pii-v1
Full breach record for Bay Bridge Administrators →Bay Bridge Administrators, LLC (BBA), a third-party administrator of insurance products, notified the New Hampshire Attorney General of a ransomware incident. An unknown actor accessed the BBA network prior to August 25, 2022, and exfiltrated data on or about September 3, 2022. The incident involved personal information including names, SSNs, driver's licenses, DOB, and medical/health insurance data. BBA engaged a cybersecurity firm, reported to DHS, and offered 24 months of credit monitoring to 159 affected New Hampshire residents.
Leak gap clock⏱ Leak >90d16 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
A leak claim by redalert about this victim predates this filing by 98 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_3e79034e4a2a5985Leak Siteredalertfiled 2022-09-22(98d gap)Verified by operator
Regulatory filings (6) · sorted by filing gap
- bd_76eac57a123a9658Montana State AGfiled 2022-12-29Verified by operator
- bd_867688de2ddd81a7Washington State AGfiled 2022-12-29Verified
- bd_868a3feb8eb3d942California State AGfiled 2022-12-29Verified by operator
- bd_d303951afc2ff846Oregon State AGfiled 2022-12-29Verified by operator
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_e3985ce504723a98Maine State AGfiled 2022-12-29Verified by operator
- bd_2076fcfdead4ed37HHS OCRfiled 2022-12-30(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/bay-bridge-administrators-20221229.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 29, 2022
- Raw hash
- 87356b937fd7c03ffee18d94dd77053823e3fb8051a628f8b9e0afabd8488529
Reporting entity
- Name
- Bay Bridge Administratorsnorm: bay bridge administrators
- Domain
- bbadmin.com
Victim entity
- Name
- Bay Bridge Administratorsnorm: bay bridge administrators
- Domain
- bbadmin.com
Incident
- Discovered
- Sep 5, 2022
- Materiality determined
- Dec 5, 2022
- Notification sent
- Dec 29, 2022
- Affected individuals
- 159
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to the Department of Homeland Security
Compliance
- Time to disclose
- 16 weeks(115 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.