HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Drivestream Inc.
bd_71871211473c181b · schema v1 · pii pii-v1
Full breach record for Drivestream Inc. →Drivestream, Inc. notified the New Hampshire Attorney General of a data event affecting 17 NH residents. Unauthorized access occurred between Dec 4-9, 2024, involving an unknown actor accessing systems and potentially exfiltrating data (names, SSNs, financial accounts). Drivestream engaged forensic investigators, notified law enforcement, and provided 12 months of credit monitoring via Epiq. Notification to individuals began Jan 10, 2025.
Leak gap clock✗ Leak >180d49 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by akira about this victim predates this filing by 343 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_bed2751c7893e79eIndiana State AGfiled 2025-11-17Verified
- bd_69e2d186b9175509Texas State AGfiled 2025-12-22(35d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/drivestream-20251117.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 17, 2025
- Raw hash
- 7f7fa2aa7361e750d83c1b32f2232cfed8db61d62031ebf8b9d427521d2a939d
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Drivestream Inc.norm: drivestream
- Domain
- drivestream.com
Incident
- Discovered
- Dec 9, 2024
- Materiality determined
- —
- Notification sent
- Jan 10, 2025
- Affected individuals
- 17
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- notifying your office on behalf of, and at the direction of, requesting customersnotified federal law enforcement regarding the incident
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 49 weeks(343 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.