Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Hanafin Financial
bd_5bfb61ca621b0cd0 · schema v1 · pii pii-v1
Full breach record for Hanafin Financial →Hanafin Financial notified the NH AG of a data security incident affecting 2 NH residents. Unauthorized access to an employee email account occurred on Jan 21, 2025, detected on Jan 28, 2025. Data exposed included names, SSNs, driver's license numbers, and financial account numbers. Notifications mailed June 3, 2025, with credit monitoring offered.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/hanafin-financial-20250604.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 4, 2025
- Raw hash
- 1a5596542329604c291d085f030cdafebaeaf9c4a1097a73d4b4a090384da848
Reporting entity
- Name
- Hanafin Financialnorm: hanafin financial
Victim entity
- Name
- Hanafin Financialnorm: hanafin financial
Incident
- Discovered
- Jan 28, 2025
- Materiality determined
- May 6, 2025
- Notification sent
- Jun 3, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- phishing_link
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.