FloatMe
bd_5fe9f30c230423fd · schema v1 · pii pii-v1
Full breach record for FloatMe →FloatMe, Corp. notified the New Hampshire Attorney General of a credential stuffing incident involving its Auth0 platform. The breach occurred December 8-9, 2025, affecting 2 New Hampshire residents. Exposed data included login credentials, mailing addresses, phone numbers, partial bank/debit card numbers, and recent financial transactions. FloatMe reset passwords, shut down the compromised endpoint, and cancelled fraudulent advances. Notifications were sent to affected individuals on January 6, 2026.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 8, 2025
Begins
Dec 9, 2025
Discovered
Jan 6, 2026
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_54811d05a129f6e32026-01-06Verified
- Maine State AGbd_cb846b9a1a7759902026-01-06Verified
- Indiana State AGbd_0823ece498a904e32026-01-05 · +1dCandidate
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.