HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Hallisey & D'Agostino, LLP
bd_6d1636b0677487b4 · schema v1 · pii pii-v1
Full breach record for Hallisey & D'Agostino, LLP →Hallisey & D’Agostino, LLP, a tax and accounting firm, reported a cybersecurity incident to the New Hampshire Attorney General on April 17, 2026. Unauthorized access occurred between September 28 and October 22, 2025. The breach potentially exposed names, Social Security numbers, driver's license numbers, and financial account information of 981 New Hampshire residents. The firm engaged forensic experts, notified the FBI, and offered 12 months of credit monitoring and identity theft protection services to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_647dbf9a138be25bIndiana State AGfiled 2026-04-17Candidate
- bd_f2f9d2090f5cd0f3Maine State AGfiled 2026-04-17Verified
- bd_ee948235b7ce7dacVermont State AGfiled 2026-04-18(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/hallisey-d-agostino-20260417.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 17, 2026
- Raw hash
- ecffc1c55782c706565ad405a8e16c631789299bf4585450d80946651b6c11e6
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Hallisey & D'Agostino, LLPnorm: hallisey d agostino
- Domain
- hdllpcpa.com
Incident
- Discovered
- Oct 21, 2025
- Materiality determined
- —
- Notification sent
- Apr 17, 2026
- Affected individuals
- 981
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 25 weeks(178 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.