HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
The May Institute, Inc.
bd_5207e8054ff815ef · schema v1 · pii pii-v1
Full breach record for The May Institute, Inc. →May Institute, Inc. notified New Hampshire residents of a data breach where unauthorized actors accessed files containing personal information (including SSNs) between Dec 5-14, 2023. The incident was discovered on Dec 14, 2023. Notices were sent starting April 1, 2024, affecting 153 NH residents. The Institute engaged law enforcement, notified HHS, and offered credit monitoring.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_137142407e3cac51Maine State AGfiled 2024-05-07Verified
- bd_24be293e36e71d44Vermont State AGfiled 2024-05-07Verified
- bd_d04a26b2741bc21cCalifornia State AGfiled 2024-05-07Verified
- bd_266c7d36ba41aac3New Hampshire State AGfiled 2024-04-01(36d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 36d gap
- bd_741bdbdf65f0748bIndiana State AGfiled 2024-04-01(36d gap)Verified
- bd_b84a1b378974faf3Vermont State AGfiled 2024-04-01(36d gap)Verified
- bd_c36bf0a5f4471980Maine State AGfiled 2024-04-01(36d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/may-institute-20240507.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 7, 2024
- Raw hash
- a5629f99c2febdb17979c01d34c86144dc5d37d532b82b08bcc30d3a574e9827
Reporting entity
- Name
- The May Institute, Inc.norm: the may institute
Victim entity
- Name
- The May Institute, Inc.norm: the may institute
Incident
- Discovered
- Dec 14, 2023
- Materiality determined
- Apr 8, 2024
- Notification sent
- Apr 1, 2024
- Affected individuals
- 153
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- notified federal law enforcementproviding written notice of this incident to relevant state regulators as requirednotifying the U.S. Department of Health and Human Services
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 21 weeks(145 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.