HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
21 Air, LLC
bd_6b60b566af0e70ba · schema v1 · pii pii-v1
Full breach record for 21 Air, LLC →21 Air, LLC notified the New Hampshire Attorney General of a cybersecurity incident discovered on June 3, 2025, involving unauthorized access to a single employee email account. The investigation determined that information for 2 New Hampshire residents was potentially accessed, including names, Social Security numbers, and government IDs. 21 Air engaged third-party specialists, reported the incident to CISA, and sent notices to affected individuals on December 11, 2025, offering 12 months of credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b3a25e188339e5cbMaine State AGfiled 2025-12-15Verified
- bd_144ddf00b9510f41Indiana State AGfiled 2025-12-11(4d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/21-air-20251215.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 15, 2025
- Raw hash
- 0f2f286b64e84fd7425cad252f3cafb119def232ffc1a013685abf9810b2c521
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- 21 Air, LLCnorm: 21 air
- Domain
- 21air.us
Incident
- Discovered
- Jun 3, 2025
- Materiality determined
- —
- Notification sent
- Dec 11, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported this incident to the Cybersecurity and Infrastructure Security Agency (“CISA”)
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 weeks(195 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.