MalwareRansomwareStolen CredentialsRansomHubData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedEmployee Data InvolvedMulti-Stage ChainPIIIDENTITY_GOVERNMENTEMPLOYMENTMediumContained
Sporn Company
bd_54215d38e3b8cb51 · schema v1 · pii pii-v1
Full breach record for Sporn Company →Sporn Company d/b/a Perrywinkle's Fine Jewelry reported a ransomware attack by RansomHub. Unauthorized access occurred between Nov 23 and Dec 2, 2024. Employee PII, including SSNs, was accessed and encrypted. 40 NH residents affected. Sporn took systems offline, engaged forensic specialists, and offers credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed40 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sporn-company-20250404.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 4, 2025
- Raw hash
- 90bdf3bbb2783ef225589c31e3096ddf930fe82c61cce1fff1f0a83248c730b0
Reporting entity
- Name
- Sporn Companynorm: sporn
Victim entity
- Name
- Sporn Companynorm: sporn
Incident
- Discovered
- Dec 2, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 40
- Data types
- PIIIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Ransomware· RansomHub
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- RansomHubExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 weeks(123 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.