HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
Washington Prime Group Inc
bd_69425c809df43c47 · schema v1 · pii pii-v1
Full breach record for Washington Prime Group Inc →Washington Prime Group Holdings L.P. notified the New Hampshire Attorney General on December 23, 2025, of a cybersecurity event affecting two New Hampshire residents. Unauthorized access occurred between July 30 and August 9, 2025. The incident involved the potential viewing or taking of names and Social Security Numbers. WPG notified federal law enforcement, provided credit monitoring via Experian, and issued notices to affected individuals and credit bureaus. The investigation is ongoing.
Leak gap clock⏱ Leak >90d19 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by worldleaks about this victim predates this filing by 137 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3acc7768b2bd05adIndiana State AGfiled 2025-12-23Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/washington-prime-group-holdings-20251223.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2025
- Raw hash
- 9366451c8c62f6f071d2ee21559123452e009687e80f1487b28e55601c2d9e46
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Washington Prime Group Incnorm: washington prime
- Domain
- wpgus.com
Incident
- Discovered
- Aug 11, 2025
- Materiality determined
- —
- Notification sent
- Dec 23, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement regarding the eventProviding written notice of this incident to relevant state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(134 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.