HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
US Graphite
bd_71a518b7582edee6 · schema v1 · pii pii-v1
Full breach record for US Graphite →U.S. Graphite Corporation notified the New Hampshire Attorney General of a cybersecurity incident. Unauthorized access occurred on July 31, 2025, discovered on August 19, 2025. Approximately one New Hampshire resident was affected, with potential exposure of names and Social Security numbers. USG reset passwords, notified law enforcement, and offered credit monitoring.
Leak gap clock✗ Leak >180d27 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by pear about this victim predates this filing by 192 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_50e13a5e74ada44bLeak Sitepearfiled 2025-08-19(192d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_0b6923de6547e823Indiana State AGfiled 2026-02-20(7d gap)Candidate
- bd_e76edd1c19a7e937Indiana State AGfiled 2026-02-20(7d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/us-graphite-20260227.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2026
- Raw hash
- 1b315f97a7091e8fe6af63478d5c9d4f24ad4b458c9b9e80f6342aaa48f3f797
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- US Graphitenorm: us graphite
- Domain
- us-graphite.com
- Industry
- manufacturing
Incident
- Discovered
- Aug 19, 2025
- Materiality determined
- —
- Notification sent
- Feb 20, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 weeks(192 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.