HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Valsoft Corporation Inc.
bd_6f5bf1a82e506b15 · schema v1 · pii pii-v1
Full breach record for Valsoft Corporation Inc. →Valsoft Corporation Inc. d/b/a AllTrust filed a supplemental notice with the New Hampshire Attorney General regarding a data event affecting 49 NH residents. Unauthorized access occurred Feb 12-15, 2024, on a non-production network managed by subsidiary Aspire USA, LLC. PII was potentially accessed. AllTrust reported to federal law enforcement, engaged forensic specialists, implemented SOC2 measures, and offered credit monitoring.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_33dcd03d26cdcefeMaryland State AGfiled 2025-02-27(68d gap)Candidate
- bd_4859b1729dbacf98Oregon State AGfiled 2025-02-27(68d gap)Verified
- bd_b79c2aca9da1c1e7New Hampshire State AGfiled 2025-02-27(68d gap)Verified
- bd_bb927d09f25ad525Indiana State AGfiled 2025-02-27(68d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 68d gap
- bd_daba09a034e6a806Washington State AGfiled 2025-02-27(68d gap)Verified
- bd_e78901becd64e305Maine State AGfiled 2025-02-27(68d gap)Verified
- bd_f4848f23e5b232f9Montana State AGfiled 2025-02-27(68d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/valsoft-corporation-alltrust-20250506.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 6, 2025
- Raw hash
- b707ffbc7aff21f214585b719a41fd0337ef86fb42a6c0c26b1a5c6ba858443f
Reporting entity
- Name
- Valsoft Corporation Inc.norm: valsoft
Victim entity
- Name
- Valsoft Corporation Inc.norm: valsoft
Incident
- Discovered
- Feb 14, 2024
- Materiality determined
- —
- Notification sent
- Feb 27, 2025
- Affected individuals
- 49
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Reported this incident to federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 months(447 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.