HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Stevens & Day, LLP
bd_75b919c82161c65d · schema v1 · pii pii-v1
Full breach record for Stevens & Day, LLP →Stevens & Day, LLP notified the New Hampshire Attorney General of a data breach affecting 29 NH residents. Unauthorized access occurred Nov 22-28, 2024; detected Nov 29, 2024. Impacted data included names, SSNs, driver's licenses, and bank account numbers. Notifications sent Aug 8, 2025. Credit monitoring offered. No misuse believed.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0b2ed7130f359d43Maine State AGfiled 2025-08-08Candidate
- bd_9ae9f0be4c0209e8Vermont State AGfiled 2025-08-08Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/stevens-day-20250808.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 8, 2025
- Raw hash
- c2072b29a74bd68bcfbed1da8e61ce8ee13e764a0fd7c17886c3f354e9355836
Reporting entity
- Name
- Stevens & Day, LLPnorm: stevens day
- Domain
- stevensdaylaw.com
Victim entity
- Name
- Stevens & Day, LLPnorm: stevens day
- Domain
- stevensdaylaw.com
Incident
- Discovered
- Nov 29, 2024
- Materiality determined
- —
- Notification sent
- Aug 8, 2025
- Affected individuals
- 29
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 36 weeks(252 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.