HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
HENNESSY ADVISORS, INC.
bd_6d4e4e25f72021c3 · schema v1 · pii pii-v1
Full breach record for HENNESSY ADVISORS, INC. →Hennessy Advisors, Inc. notified the New Hampshire Attorney General of a security incident discovered on March 30, 2025. Unauthorized access to systems resulted in the exfiltration of personal information for 95 New Hampshire residents, including names, SSNs, driver's license numbers, and financial account data. The breach was confirmed in December 2025, and notifications were sent to affected individuals on February 23, 2026, offering credit monitoring services.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_072c9ab8534cfc81California State AGfiled 2026-02-24Verified
- bd_41991ab4574f8c98Maine State AGfiled 2026-02-24Verified by operator
- bd_4a3d6923a18d23b5Texas State AGfiled 2026-02-25(1d gap)Verified by operator
- bd_155d62cf97956468Indiana State AGfiled 2026-02-23(1d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_d11bdc8476440748Vermont State AGfiled 2026-02-23(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/hennessy-advisors-20260224.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 24, 2026
- Raw hash
- ae4a5fec1e8d7b54cdfb763fcb459139be11f3b7d9aeffe2ae7c164a29c5cabf
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- HENNESSY ADVISORS, INC.norm: hennessy advisors
- Domain
- hennessyadvisors.com
Incident
- Discovered
- Mar 30, 2025
- Materiality determined
- —
- Notification sent
- Feb 23, 2026
- Affected individuals
- 95
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 47 weeks(331 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.