HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Oklahoma Tax Commission
bd_59f67e4c69e02380 · schema v1 · pii pii-v1
Full breach record for Oklahoma Tax Commission →Oklahoma Tax Commission notified New Hampshire AG of unauthorized access to OkTAP system between July 5, 2024 and Dec 20, 2025. 18 NH residents affected; data included names and SSNs. Discovered Dec 2025. Notifications sent March 27, 2026. Response included forensic investigation, IRS cooperation, system safeguards, and 12-month credit monitoring.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_106ec023e6c2444aMaine State AGfiled 2026-03-27Candidate
- bd_9761396221115132California State AGfiled 2026-03-27Verified
- bd_c855c9473a93d594Indiana State AGfiled 2026-03-27Verified
- bd_d4fd04889cc15d7cVermont State AGfiled 2026-03-27Candidate
Show 1 more filing ↓Show fewer ↑up to 3d gap
- bd_1009fe78a84233d0Texas State AGfiled 2026-03-30(3d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/oklahoma-tax-commission-20260327.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2026
- Raw hash
- ae51bc0e985f4bcebd1101bbb616608499290786e539b31166e54ac315ecf81b
Reporting entity
- Name
- Oklahoma Tax Commissionnorm: oklahoma tax commission
- Domain
- tax.ok.gov
Victim entity
- Name
- Oklahoma Tax Commissionnorm: oklahoma tax commission
- Domain
- tax.ok.gov
Incident
- Discovered
- Dec 1, 2025
- Materiality determined
- —
- Notification sent
- Mar 27, 2026
- Affected individuals
- 18
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- cooperating with the IRS to further their investigation so they can monitor fraudulent tax filing activityproviding written notice of this event to relevant state privacy regulators and to the three (3) major credit reporting agencies: Equifax, Experian, and TransUnion
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.