HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumActive
Credit Technologies, Inc
bd_76d779580c553f52 · schema v1 · pii pii-v1
Full breach record for Credit Technologies, Inc →Credit Technologies, Inc. notified the New Hampshire Attorney General of a data security incident occurring on or about September 9, 2025. Unauthorized access to systems resulted in the acquisition of personal information, including names, SSNs, driver's licenses, financial account numbers, and health information. Approximately one New Hampshire resident was affected. The company engaged external cybersecurity experts, discovered the PII impact on April 10, 2026, and began notifying affected individuals on April 27, 2026, offering 12 months of credit monitoring via Kroll.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_30efa5fba8f202faIndiana State AGfiled 2026-04-27Candidate
- bd_5bd4b501efa099a4Maine State AGfiled 2026-04-27Verified by operator
- bd_5fe5e5e4deb41ac2Vermont State AGfiled 2026-04-27Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/credit-technologies-20260427.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 27, 2026
- Raw hash
- 6cdd43f79cbc1f28b29b614b7c944d192f2428f3a3133124882b137337946856
Reporting entity
- Name
- Credit Technologies, Incnorm: credit technologies
Victim entity
- Name
- Credit Technologies, Incnorm: credit technologies
Incident
- Discovered
- Apr 10, 2026
- Materiality determined
- —
- Notification sent
- Apr 27, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 days(17 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.