HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
GiaCare
bd_6fef7171d0ac6eea · schema v1 · pii pii-v1
Full breach record for GiaCare →GiaCare, Inc. notified the New Hampshire Attorney General of a data security incident involving its third-party vendor, Gladinet CentreStack. An unauthorized third party accessed and exfiltrated files containing one New Hampshire resident's name, driver's license number, and Social Security number on or about December 6, 2025. GiaCare discovered the vulnerability on December 23, 2025, migrated data off the platform, and offered one year of credit monitoring to the affected individual.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/giacare-20260123.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 23, 2026
- Raw hash
- 54a9b83f1cbfc882db78775dca335793efb0a62340798c8c9e409d9101ecb4c5
Reporting entity
- Name
- GiaCarenorm: giacare
- Domain
- giacare.com
Victim entity
- Name
- GiaCarenorm: giacare
- Domain
- giacare.com
Incident
- Discovered
- Dec 23, 2025
- Materiality determined
- —
- Notification sent
- Jan 23, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.