HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Stevens & Lee, P.C.
bd_4656c94467fb53f8 · schema v1 · pii pii-v1
Full breach record for Stevens & Lee, P.C. →Stevens & Lee, a Pennsylvania law firm, notified the New Hampshire Attorney General of a data breach discovered on June 28, 2021. Unauthorized access to systems may have exposed names, driver's license numbers, and Social Security numbers of 396 NH residents. Notifications were sent on April 7, 2022. The firm engaged forensic investigators and law enforcement, enhanced network security, and provided 24 months of credit monitoring and identity restoration services through IDX.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_2a5004aeb0b0d85eWashington State AGfiled 2022-04-08Verified
- bd_6f048ed8e6069b6dCalifornia State AGfiled 2022-04-08Verified
- bd_9e8a88c402d7b574Montana State AGfiled 2022-04-07(1d gap)Verified
- bd_3ca4b4db5aeb36fcMaine State AGfiled 2022-04-11(3d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 101d gap
- bd_c7efad509311ce92Maine State AGfiled 2021-12-30(99d gap)Verified
- bd_94e9b15529337432Maine State AGfiled 2021-12-28(101d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/stevens-lee-20220408.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 8, 2022
- Raw hash
- c68c1c60af2d6a01314c8915e526b4736320232862d438166c53d468e15cf3d0
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- Stevens & Lee, P.C.norm: stevens lee
Incident
- Discovered
- Jun 28, 2021
- Materiality determined
- —
- Notification sent
- Apr 7, 2022
- Affected individuals
- 396
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 41 weeks(284 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.