GRAYROBINSON, P.A.
bd_794b695cf033f8ab · schema v1 · pii pii-v1
Full breach record for GRAYROBINSON, P.A. →GrayRobinson, P.A., a law firm, notified the New Hampshire Attorney General that an unauthorized actor accessed its network between March 5 and March 24, 2025. GrayRobinson discovered the breach on April 13, 2026, after a forensic investigation. The incident potentially exposed personal information, including names, DOBs, SSNs, driver's license numbers, financial account info, and medical data, for 41 New Hampshire residents. GrayRobinson reported the incident to law enforcement, engaged external cybersecurity professionals, and is offering one year of complimentary credit monitoring to affected residents.
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_cca7851fcf929bc5Vermont State AGfiled 2026-05-05(2d gap)Verified
- bd_aa3a4069dcb4c338California State AGfiled 2026-05-04(3d gap)Verified
- bd_5befb58f749743e9New Hampshire State AGfiled 2026-04-29(8d gap)Verified
- bd_35cc442280a9189cMontana State AGfiled 2026-04-24(13d gap)Candidate
Show 3 more filings ↓Show fewer ↑up to 13d gap
- bd_70a89970a20e2cd6HHS OCRfiled 2026-04-24(13d gap)Verified
- bd_97efcfd5f4cb89baCalifornia State AGfiled 2026-04-24(13d gap)Verified
- bd_d2707ef1537a6e5bIndiana State AGfiled 2026-04-24(13d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/grayrobinson-20260507.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 7, 2026
- Raw hash
- cbbb2eb9cdd448d36f9b92ef9c36849b0d4c8981e1928c7f00f43c42f71abe9f
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- GRAYROBINSON, P.A.norm: grayrobinson
Incident
- Discovered
- Apr 13, 2026
- Materiality determined
- —
- Notification sent
- May 4, 2026
- Affected individuals
- 41
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.