HackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)Delayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Informa
bd_4f8604f7f2c749bb · schema v1 · pii pii-v1
Full breach record for Informa →Informa filed a supplemental notice to the New Hampshire AG regarding a security incident involving Oracle E-Business Suite. Unauthorized access occurred between August 11-18, 2025, exploiting a zero-day vulnerability before public disclosure. The breach affected 40 New Hampshire residents, exposing names, SSNs, DOBs, and bank account information. Informa engaged forensic experts, notified law enforcement, and offered 24 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed40 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/informa-entities-20260421.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2026
- Raw hash
- 2c883dc2288b6948864650e70361af895d620e4e511a50c47898b9ea34763b2b
Reporting entity
- Name
- Informanorm: informa
- Domain
- informa.com
Victim entity
- Name
- Informanorm: informa
- Domain
- informa.com
Incident
- Discovered
- Nov 1, 2025
- Materiality determined
- —
- Notification sent
- Apr 17, 2026
- Affected individuals
- 40
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed supplemental notice with New Hampshire Office of the Attorney General, Consumer Protection Bureau
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 weeks(171 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.