HackingPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Sterling
bd_61b6c7f9d335b96b · schema v1 · pii pii-v1
Full breach record for Sterling →Sterling Seacrest Pritchard, Inc. (SSP) submitted a supplemental notice to the New Hampshire Attorney General regarding a data security incident involving unauthorized access to SSP's email environment. The incident occurred between August 12-13, 2025, and was discovered on August 13, 2025. The breach potentially exposed names and Social Security Numbers of 15 New Hampshire residents. SSP engaged independent experts, secured the email account, and offered 12 months of credit monitoring and identity protection services through Kroll to affected individuals.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_ba9145ecccf11312Maine State AGfiled 2026-05-21(2d gap)Verified by operator
- bd_5d155bf5e75159b1New Hampshire State AGfiled 2026-06-17(29d gap)Verified
- bd_a2bac98dc6f5e945New Hampshire State AGfiled 2026-03-27(53d gap)Candidate
- bd_3be48f35f380de72Indiana State AGfiled 2026-03-25(55d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 55d gap
- bd_d3c3d7329b967472Indiana State AGfiled 2026-03-25(55d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sterling-seacrest-pritchard-20260519.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 19, 2026
- Raw hash
- 9d9aa8977b3d5b337af2daa5c519d0e7ac2e49443cd865fb0a2e3c6570cd2cd3
Reporting entity
- Name
- Sterlingnorm: sterling
- Domain
- sterling.com
Victim entity
- Name
- Sterlingnorm: sterling
- Domain
- sterling.com
Incident
- Discovered
- Aug 13, 2025
- Materiality determined
- —
- Notification sent
- May 19, 2026
- Affected individuals
- 15
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email CollectionT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 40 weeks(279 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.