HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICAUTHENTICATIONLowContained
Moses-Weitzman Health System, Inc.
bd_5a05001fa8c1ba75 · schema v1 · pii pii-v1
Full breach record for Moses-Weitzman Health System, Inc. →Moses-Weitzman Health System, Inc. notified the NH Attorney General of a security breach discovered on Jan 2, 2025. A sophisticated criminal actor accessed IT systems, exfiltrating data including benefits and credentialing info for 5 NH residents and other employees. MWHS engaged forensic investigators, revoked access, notified law enforcement, and offered identity theft protection services.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_06c323e4f068c974Maine State AGfiled 2025-01-30Candidate
- bd_abcbf8032b31cc54Maryland State AGfiled 2025-01-30Verified
- bd_b72ef11708d0139aIndiana State AGfiled 2025-01-30Verified
- bd_de0962eda247ff49Vermont State AGfiled 2025-01-30Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/moses-weitzman-health-system-20250130.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2025
- Raw hash
- 8c07d53410599843130e64cf8daf822f54ec024ae97bda9b4d74fc4a8efb5add
Reporting entity
- Name
- Moses-Weitzman Health System, Inc.norm: moses weitzman health system
Victim entity
- Name
- Moses-Weitzman Health System, Inc.norm: moses weitzman health system
Incident
- Discovered
- Jan 2, 2025
- Materiality determined
- —
- Notification sent
- Jan 30, 2025
- Affected individuals
- 5
- Data types
- IDENTITY_BASICAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.