HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Toast, Inc.
bd_61f90fdd5e6db86e · schema v1 · pii pii-v1
Full breach record for Toast, Inc. →Toast, Inc. notified New Hampshire authorities of a security event involving suspicious login activity on its Payroll application. Unauthorized actors accessed employee profiles containing Social Security numbers and basic PII between June 30 and July 17, 2025. Approximately one New Hampshire resident was affected. Toast reset passwords, engaged forensic investigators, notified law enforcement, and offered identity monitoring services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/toast-20250905.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2025
- Raw hash
- 28319603bf359abf49a0979cb0466b55a780a2466213506a3563532e9895bbc0
Reporting entity
- Name
- Orrick, Herrington & Sutcliffe LLPnorm: orrick herrington sutcliffe
- Domain
- orrick.com
Victim entity
- Name
- Toast, Inc.norm: toast
Incident
- Discovered
- Jul 1, 2025
- Materiality determined
- —
- Notification sent
- Sep 5, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(66 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.