HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
New Hampshire Historical Society
bd_454407f5e00ef36c · schema v1 · pii pii-v1
Full breach record for New Hampshire Historical Society →The New Hampshire Historical Society experienced a cybersecurity incident on or about September 5, 2025, involving unauthorized access to its network. The breach compromised personal information of approximately 3,125 individuals, including names, addresses, Social Security numbers, and financial account data. The Society engaged forensic investigators, notified law enforcement, and provided credit monitoring services to affected individuals. The incident is currently contained.
Vermont clock✗ VT AG >45 bday30 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6a2e16e40b883f09New Hampshire State AGfiled 2026-04-01Verified
- bd_a1b8c9ff8dea473fIndiana State AGfiled 2026-04-01Verified
- bd_f876bba9e20e576fMaine State AGfiled 2026-04-01Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-04-01-nh-historical-society-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 1, 2026
- Raw hash
- ec0772201e67038ca19831c59581f0f88f8f32cc32313504f82952a8b060ac53
Reporting entity
- Name
- New Hampshire Historical Societynorm: new hampshire historical society
- Domain
- nhhs.org
Victim entity
- Name
- New Hampshire Historical Societynorm: new hampshire historical society
- Domain
- nhhs.org
Incident
- Discovered
- Sep 5, 2025
- Materiality determined
- —
- Notification sent
- Apr 1, 2026
- Affected individuals
- 3,125
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Vermont Attorney General's Office
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 30 weeks(208 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.