HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
PLAZA HOME MORTGAGE, INC.
bd_452429ca9a0fc4b8 · schema v1 · pii pii-v1
Full breach record for PLAZA HOME MORTGAGE, INC. →Plaza Home Mortgage, Inc. reported a security incident to the New Hampshire Attorney General involving unauthorized access to an employee's computer on or around February 17, 2026. The breach potentially affected 1,090 New Hampshire residents, exposing personal information including names, addresses, Social Security numbers, birth dates, driver's license numbers, and mortgage loan application data. Notices were sent to affected individuals on May 29, 2026, offering 12 months of credit monitoring and identity theft protection.
Leak gap clock⏱ Leak >90d16 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
A leak claim by silentransomgroup about this victim predates this filing by 103 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_08868d749599b323Indiana State AGfiled 2026-05-29(13d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/plaza-home-mortgage-20260611.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 11, 2026
- Raw hash
- 01fe603d4d66481466dc605a1581c3a87a7835a18cd1403017d9de1dead2bce2
Reporting entity
- Name
- HINSHAW & CULBERTSON LLPnorm: hinshaw culbertson
Victim entity
- Name
- PLAZA HOME MORTGAGE, INC.norm: plaza home mortgage
- Domain
- plazahomemortgage.com
- Industry
- financial_services
Incident
- Discovered
- Feb 17, 2026
- Materiality determined
- —
- Notification sent
- May 29, 2026
- Affected individuals
- 1,090
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 weeks(114 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.