HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Rain Bird Corporation
bd_66ffdc5d32ba46ff · schema v1 · pii pii-v1
Full breach record for Rain Bird Corporation →Rain Bird Corporation notified the New Hampshire Attorney General of a data event affecting 99 state residents. Suspicious activity on the Rain Bird Web Store between February 11 and September 5, 2025, resulted in unauthorized access to names, credit card numbers, CVVs, and access codes. Rain Bird engaged third-party specialists, notified affected individuals, and provided 12 months of credit monitoring via TransUnion.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_086fcc56cd69f962Washington State AGfiled 2025-12-11Candidate
- bd_0bbdec6ac64a035aIndiana State AGfiled 2025-12-11Verified
- bd_1e46c37f904f2774Vermont State AGfiled 2025-12-11Verified
- bd_24aed5b22c9d73f8Oregon State AGfiled 2025-12-11Verified
Show 4 more filings ↓Show fewer ↑up to 1d gap
- bd_bf8cf647d0c6afb9California State AGfiled 2025-12-11Verified
- bd_ea590b250b73be3fMontana State AGfiled 2025-12-11Verified
- bd_f93e313af4292b32Maine State AGfiled 2025-12-11Verified
- bd_11c0a2c1f7bdc81aTexas State AGfiled 2025-12-12(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/rain-bird-20251211.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 11, 2025
- Raw hash
- c62326543e9a062c9698f9ab505b8b8e285ad47957281ae8426d64259625e742
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Rain Bird Corporationnorm: rain bird
- Domain
- rainbird.com
Incident
- Discovered
- Jul 25, 2025
- Materiality determined
- —
- Notification sent
- Dec 11, 2025
- Affected individuals
- 99
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 weeks(139 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.