HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
PHILADELPHIA CORPORATION FOR AGING
bd_46900783fc961717 · schema v1 · pii pii-v1
Full breach record for PHILADELPHIA CORPORATION FOR AGING →Philadelphia Corporation for Aging (PCA) notified the New Hampshire Attorney General of a cybersecurity event affecting 5 NH residents. Unauthorized access occurred between July 10 and July 25, 2025, resulting in the copying of names, SSNs, DOBs, credit card numbers, financial account info, and limited medical data. PCA retained forensic specialists, reported to law enforcement, and provided 12 months of credit monitoring. Notification letters were mailed on November 4, 2025.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_19b4807a7d9923caIndiana State AGfiled 2025-11-04Verified
- bd_1a39b4bacb780e2eVermont State AGfiled 2025-11-04Verified
- bd_815e9ddbd682bc81Maine State AGfiled 2025-11-04Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/philadelphia-coporation-aging-20251104.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 4, 2025
- Raw hash
- d111e0c16317df24d784fd5df84be558b8cb85bd896bc1eae4150c933afb1928
Reporting entity
- Name
- PHILADELPHIA CORPORATION FOR AGINGnorm: philadelphia corporation for aging
Victim entity
- Name
- PHILADELPHIA CORPORATION FOR AGINGnorm: philadelphia corporation for aging
Incident
- Discovered
- Jul 25, 2025
- Materiality determined
- —
- Notification sent
- Nov 4, 2025
- Affected individuals
- 5
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 weeks(102 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.