HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
USA Duct
bd_5926e66c0d656582 · schema v1 · pii pii-v1
Full breach record for USA Duct →U.S. Duct, Inc. notified the New Hampshire AG that on Jan 15, 2026, an unauthorized third party accessed its network. The incident was contained. Analysis confirmed access to employee/dependent PII (name, DOB, SSN). One NH resident affected. Remediation included credential resets, monitoring, and 12 months of credit monitoring services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/us-duct-20260424.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 24, 2026
- Raw hash
- c519fbbb52df9b47b3ef62b1ef59ed46a020733b073255fb1ebeb606e1056462
Reporting entity
- Name
- USA Ductnorm: usa duct
- Domain
- usaduct.com
Victim entity
- Name
- USA Ductnorm: usa duct
- Domain
- usaduct.com
Incident
- Discovered
- Jan 15, 2026
- Materiality determined
- —
- Notification sent
- Apr 20, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(99 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.