HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Kaplan North America, LLC
bd_5195761b433bf377 · schema v1 · pii pii-v1
Full breach record for Kaplan North America, LLC →Kaplan North America, LLC notified the New Hampshire Attorney General of a cybersecurity incident where an unauthorized actor accessed servers between Oct 30 and Nov 18, 2025. The breach exposed names, SSNs, and driver's license numbers of 11,653 NH residents. Notifications were sent on March 17, 2026, offering one year of credit monitoring.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_03ac6b2ac5b6d4a6Indiana State AGfiled 2026-03-17Candidate
- bd_1e887c69b831ca2bCalifornia State AGfiled 2026-03-17Verified
- bd_3af6a5c8e815660bMaine State AGfiled 2026-03-17Verified
- bd_43bbc55f2a1fdb41South Carolina State AGfiled 2026-03-17Verified
Show 6 more filings ↓Show fewer ↑up to 1d gap
- bd_6cd40678378733bbIowa State AGfiled 2026-03-17Verified
- bd_7eccbae29faca690Washington State AGfiled 2026-03-17Verified
- bd_9cd5c500ae4a6563Delaware State AGfiled 2026-03-17Verified
- bd_a1a2590136ab7eddVermont State AGfiled 2026-03-17Verified
- bd_dde3052cb27cb9c5Oregon State AGfiled 2026-03-17Verified
- bd_2163f3082d7a92d9Texas State AGfiled 2026-03-18(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/kaplan-north-america-20260317.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 17, 2026
- Raw hash
- 800aa4167061dee3a2bb3d025b80c5cdcfd8834d46a57f23775afa157c03e263
Reporting entity
- Name
- Kaplan North America, LLCnorm: kaplan north america
- Domain
- kaplan.com
Victim entity
- Name
- Kaplan North America, LLCnorm: kaplan north america
- Domain
- kaplan.com
Incident
- Discovered
- Feb 21, 2026
- Materiality determined
- —
- Notification sent
- Mar 17, 2026
- Affected individuals
- 11,653
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.