MalwareRansomwareRansom DemandedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Phil Smith Automotive Group
bd_429e89d3c30c21cc · schema v1 · pii pii-v1
Full breach record for Phil Smith Automotive Group →Phil Smith Automotive Group reported a ransomware attack in early February 2025 affecting its IT systems. The incident may have exposed the personal information, including SSNs and driver's license numbers, of 19 New Hampshire residents. The company notified the FBI, engaged cybersecurity specialists, and began notifying affected individuals on July 31, 2025, offering two years of credit monitoring.
Leak gap clock⏱ Leak >90d26 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
A leak claim by dragonforce about this victim predates this filing by 173 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_30dee3ff79df90bbMaine State AGfiled 2025-07-31Candidate
- bd_fb43a564bb05bb3eIndiana State AGfiled 2025-07-31Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/phil-smith-automotive-group-20250731.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 31, 2025
- Raw hash
- 50f19357a3daa40c6a638b5164476db38749d05d907947acb6e1b000f1709519
Reporting entity
- Name
- Phil Smith Automotive Groupnorm: phil smith automotive
- Domain
- philsmithauto.com
Victim entity
- Name
- Phil Smith Automotive Groupnorm: phil smith automotive
- Domain
- philsmithauto.com
Incident
- Discovered
- Feb 1, 2025
- Materiality determined
- —
- Notification sent
- Jul 31, 2025
- Affected individuals
- 19
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified U.S. federal law enforcement, including the Federal Bureau of Investigation (“FBI”)
Compliance
- Time to disclose
- 26 weeks(180 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.