HackingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
SAX
bd_70f3b36fdd6d270f · schema v1 · pii pii-v1
Full breach record for SAX →Sax, LLP notified New Hampshire AG John Formella on December 22, 2025, regarding a data security incident discovered on August 7, 2024. Approximately 406 New Hampshire residents were affected. Unauthorized access to Sax's network resulted in the potential exposure of personal information, including Social Security Numbers, dates of birth, driver's license numbers, and passport numbers. Sax engaged independent cybersecurity experts, notified the FBI, and provided 12 months of credit monitoring and identity protection services through Epiq to affected individuals.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_03368ea6c198e1b3Montana State AGfiled 2025-12-22Verified
- bd_6b0331732b1d6680Maine State AGfiled 2025-12-22Verified
- bd_a57bf44b11d3263aCalifornia State AGfiled 2025-12-22Candidate
- bd_ce441aca74d4f237Vermont State AGfiled 2025-12-22Verified
Show 4 more filings ↓Show fewer ↑up to 7d gap
- bd_db6dcf921571714aSouth Carolina State AGfiled 2025-12-23(1d gap)Verified
- bd_556c3ae504f7e82cDelaware State AGfiled 2025-12-16(6d gap)Verified
- bd_a0269a5e4239280fIndiana State AGfiled 2025-12-16(6d gap)Verified
- bd_1ef0f101196477a7Texas State AGfiled 2025-12-29(7d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sax-20251222.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2025
- Raw hash
- 3a9a85332ca3c81e55d7c46d57af2129c8734cda2f705aa4f310bbeb76175af3
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- SAXnorm: sax
- Domain
- saxadvisorygroup.com
Incident
- Discovered
- Aug 7, 2024
- Materiality determined
- —
- Notification sent
- Dec 16, 2025
- Affected individuals
- 406
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation of the incident and will provide whatever cooperation is necessary to hold the perpetrators accountable
Compliance
- Time to disclose
- 17 months(502 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.