Churchill Claims Services, Inc.
bd_533d0ae003a5405d · schema v1 · pii pii-v1
Full breach record for Churchill Claims Services, Inc. →Churchill Claims Services, Inc. notified the New Hampshire Attorney General of a data security incident discovered on September 14, 2025. An unauthorized actor accessed the network and potentially downloaded files containing personal information of 12 NH residents, including names, SSNs, driver's license numbers, payment card numbers, usernames, passwords, and medical/health insurance information. Notifications were sent on April 27, 2026, offering credit monitoring via TransUnion/Cyberscout. Churchill engaged cybersecurity experts and implemented additional security measures.
Linked disclosures
Why this link?Ransomware claims (1)
- bd_f8817f2de5186b0eLeak Sitesecurotropfiled 2025-10-09(200d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_a2237f9466e1fa70Indiana State AGfiled 2026-04-27Verified
- bd_2b2dc5068bbe5e92Vermont State AGfiled 2026-04-28(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/churchill-claims-services-20260427.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 27, 2026
- Raw hash
- 9c17ff409aeccf690bcae5fa5b564a46b396778f4b370ce6aad1b2b47e2a7b07
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Churchill Claims Services, Inc.norm: churchill claims
- Domain
- churchill-claims.com
Incident
- Discovered
- Sep 14, 2025
- Materiality determined
- —
- Notification sent
- Apr 27, 2026
- Affected individuals
- 12
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 32 weeks(225 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.