HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICMediumContained
pewag
bd_484f9ae9b9ef33d3 · schema v1 · pii pii-v1
Full breach record for pewag →pewag, Inc. notified the New Hampshire Attorney General of a data event discovered on April 8, 2026, involving 16 NH residents. Unauthorized access resulted in the copying of names, SSNs, driver's licenses, passport numbers, financial account numbers, and health/medical information. pewag engaged forensic experts, notified law enforcement, and offered 12 months of credit monitoring via Cyberscout/TransUnion. Notifications were mailed on May 15, 2026.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_373cb109f9451d66Maine State AGfiled 2026-05-15Candidate
- bd_ac479561543e9d71Indiana State AGfiled 2026-05-15Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pewag-20260515.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 15, 2026
- Raw hash
- cbb079f24a04bbd022ff2c455048fbc8d9e9ce10339d8b4e6cfe0347b39552ff
Reporting entity
- Name
- pewag
- Domain
- pewag.com
Victim entity
- Name
- pewag
- Domain
- pewag.com
Incident
- Discovered
- Apr 8, 2026
- Materiality determined
- —
- Notification sent
- May 15, 2026
- Affected individuals
- 16
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.