Social EngineeringPhishingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Archwest Funding, LLC and Archwest Lending, LLC
bd_77be2841aa8a374b · schema v1 · pii pii-v1
Full breach record for Archwest Funding, LLC and Archwest Lending, LLC →Archwest Funding, LLC and Archwest Lending, LLC notified the New Hampshire Attorney General of a data security incident involving one NH resident. Unauthorized access occurred on January 23, 2026, via a deceptive message (phishing) targeting an employee email account. The attacker may have viewed emails and attachments containing the resident's name, SSN, driver's license number, and financial account information. Archwest secured the account, investigated, and offered 12 months of credit monitoring and identity theft protection services to the affected individual.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5d73470fcbe46303Massachusetts State AGfiled 2026-06-01(29d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/archwest-funding-archwest-lending-20260630.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2026
- Raw hash
- 36eb85d9b773601a2c866e8635263438981507bc565e957113be6764b1b3a1e8
Reporting entity
- Name
- Bradley Arant Boult Cummings LLPnorm: bradley arant boult cummings
- Industry
- professional_services
Victim entity
- Name
- Archwest Funding, LLC and Archwest Lending, LLCnorm: archwest funding llc and archwest lending
- Industry
- financial_services
Incident
- Discovered
- May 12, 2026
- Materiality determined
- —
- Notification sent
- Jun 25, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Consumer Protection & Antitrust Bureau
- Initial access
- phishing_link
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.