HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
CHURCHILL MORTGAGE CORPORATION
bd_6e06748a26721b01 · schema v1 · pii pii-v1
Full breach record for CHURCHILL MORTGAGE CORPORATION →Churchill Mortgage Corporation notified the New Hampshire Attorney General of a security incident involving unauthorized access to an employee's email account between November 13-18, 2021. The breach exposed personal information, including names, Social Security numbers, and financial account numbers, of 20 New Hampshire residents. Churchill secured the account, offered one year of credit monitoring via Experian, and sent notification letters on April 12, 2022.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed20 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/churchill-mortgage-20220412.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 12, 2022
- Raw hash
- 6e212192409d50b21fea434e27de2d0d34f7b026d7ffe3413f126cabc28ab02e
Reporting entity
- Name
- CHURCHILL MORTGAGE CORPORATIONnorm: churchill mortgage
Victim entity
- Name
- CHURCHILL MORTGAGE CORPORATIONnorm: churchill mortgage
Incident
- Discovered
- Feb 10, 2022
- Materiality determined
- —
- Notification sent
- Apr 12, 2022
- Affected individuals
- 20
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Attorney General John M. Formella
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.