HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICLowContained
Graphique de France
bd_48e5087031c11575 · schema v1 · pii pii-v1
Full breach record for Graphique de France →Graphique De France notified the NH Attorney General of a data incident occurring on March 14, 2025, involving unauthorized access to employee personal information. 20 NH residents were affected. The company engaged forensic investigators, reported to federal law enforcement, and offered credit monitoring services.
Leak gap clock⏱ Leak >30d8 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
A leak claim by lockbit_3 about this victim predates this filing by 53 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (3)
- bd_e408ef27c1b6c1d3Leak Sitelockbit5filed 2025-04-06(29d gap)Verified
- bd_9426516e67ad823cLeak Sitelockbit_3filed 2025-04-06(30d gap)Verified
- bd_5562c77f3041a9a9Leak Sitelockbit_3filed 2025-03-14(53d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_c03903a8cac06e3aMaine State AGfiled 2025-05-06Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/graphique-de-france-20250506.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 6, 2025
- Raw hash
- c46b52057bb8be58f71253a3ce8b83207f1d4d4d351d7ccccdc3c37789504675
Reporting entity
- Name
- Graphique de Francenorm: graphique de france
- Domain
- graphiquedefrance.com
Victim entity
- Name
- Graphique de Francenorm: graphique de france
- Domain
- graphiquedefrance.com
Incident
- Discovered
- Mar 14, 2025
- Materiality determined
- Apr 7, 2025
- Notification sent
- May 6, 2025
- Affected individuals
- 20
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported this incident to federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.