HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
U.S. 1031 Exchange Services. Inc.
bd_6bfb2470723c5ada · schema v1 · pii pii-v1
Full breach record for U.S. 1031 Exchange Services. Inc. →U.S. 1031 Exchange Services, Inc. notified the New Hampshire Attorney General of a cybersecurity incident discovered on October 16, 2025. An unauthorized actor accessed files containing names, addresses, Social Security numbers, and bank account/routing numbers. 882 individuals were affected, including 5 New Hampshire residents. Notification letters were mailed on April 23, 2026. The company engaged forensic investigators, shut down workstations, reset passwords, implemented MFA, and provided 12 months of credit monitoring.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_2de9fe731e5d0b51Maine State AGfiled 2026-04-23Candidate
- bd_eeeb90f271235d7fIndiana State AGfiled 2026-04-23Verified
- bd_f3d0dcf027559105Indiana State AGfiled 2026-04-23Verified
- bd_83579b33e44da3b6Maine State AGfiled 2026-05-08(15d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 18d gap
- bd_af10ef47e2dbedc9New Hampshire State AGfiled 2026-05-08(15d gap)Candidate
- bd_861a4533ccb00907Vermont State AGfiled 2026-05-11(18d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/us-1031-exchange-services-20260423.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- 9a4dbc8827dc15d267508378ac3eef17ace3e73b4a59abedc008d404454f2581
Reporting entity
- Name
- U.S. 1031 Exchange Services. Inc.norm: us 1031 exchange
Victim entity
- Name
- U.S. 1031 Exchange Services. Inc.norm: us 1031 exchange
Incident
- Discovered
- Oct 16, 2025
- Materiality determined
- —
- Notification sent
- Apr 23, 2026
- Affected individuals
- 882
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 weeks(189 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.