HackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
GRAYROBINSON, P.A.
bd_5befb58f749743e9 · schema v1 · pii pii-v1
Full breach record for GRAYROBINSON, P.A. →GrayRobinson, P.A. notified the New Hampshire Attorney General of a cybersecurity incident affecting 34 NH residents. Unauthorized access occurred between March 5, 2025, and March 24, 2025. GrayRobinson discovered the breach on April 13, 2026, after a forensic investigation. Impacted data included names, DOB, medical info, financial account info, driver's license numbers, and SSNs. GrayRobinson secured the network, reported to law enforcement, and offered 12 months of credit monitoring. Notification letters were mailed on April 24, 2026.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_aa3a4069dcb4c338California State AGfiled 2026-05-04(5d gap)Verified
- bd_35cc442280a9189cMontana State AGfiled 2026-04-24(5d gap)Candidate
- bd_70a89970a20e2cd6HHS OCRfiled 2026-04-24(5d gap)Verified
- bd_97efcfd5f4cb89baCalifornia State AGfiled 2026-04-24(5d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 8d gap
- bd_d2707ef1537a6e5bIndiana State AGfiled 2026-04-24(5d gap)Verified
- bd_cca7851fcf929bc5Vermont State AGfiled 2026-05-05(6d gap)Verified
- bd_794b695cf033f8abNew Hampshire State AGfiled 2026-05-07(8d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/grayrobinson-20260429.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 29, 2026
- Raw hash
- 4a704b0e790d529e776f1f99419ec5433622262266114f7231a5857571da5988
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- GRAYROBINSON, P.A.norm: grayrobinson
Incident
- Discovered
- Apr 13, 2026
- Materiality determined
- —
- Notification sent
- Apr 24, 2026
- Affected individuals
- 34
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.