Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Point5
bd_52dc913a7de572fb · schema v1 · pii pii-v1
Full breach record for Point5 →Point5 Managed Services, LLC notified the New Hampshire Attorney General of a data incident occurring on or about October 10, 2025. A phishing attack led to unauthorized access to the organization's Office 365 environment, resulting in the compromise of approximately 3 New Hampshire residents' personal information, including Social Security numbers and driver's license numbers. The company migrated to Google Workspace, rotated credentials, and implemented enhanced security measures including MFA. Affected individuals were notified and offered 24 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/point5-managed-services-20251125.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 25, 2025
- Raw hash
- 2450d1e053e01c08c5d2772f74f63239957dca08efe107ab566df57b2e202e37
Reporting entity
- Name
- Point5norm: point5
- Domain
- point5.net
Victim entity
- Name
- Point5norm: point5
- Domain
- point5.net
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 3
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Office (Consumer Protection Bureau)
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.