HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Builders Insurance (A Mutual Captive Company)
bd_7d6454372ca3b644 · schema v1 · pii pii-v1
Full breach record for Builders Insurance (A Mutual Captive Company) →Builders Mutual Insurance Company notified New Hampshire residents on September 29, 2023, of a cybersecurity incident discovered on December 14, 2022. Unauthorized access to the network occurred starting December 14, 2022, with file copying on December 15, 2022. The breach potentially exposed personal information, including names and government IDs, of 7 New Hampshire residents. Builders Mutual engaged third-party specialists, notified federal law enforcement, and is offering credit monitoring services through Experian.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_00e6bd7a5cc86b96Maine State AGfiled 2023-09-29Candidate
- bd_aa63b02d952af452Vermont State AGfiled 2023-09-29Verified
- bd_ab2cf2fa582e4a20Montana State AGfiled 2023-09-29Verified by operator
- bd_3054d507945b1361New Hampshire State AGfiled 2023-10-19(20d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/builders-mutual-insurance-company-20230929.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 29, 2023
- Raw hash
- 0fddebe732892a071a7e57a5e3368d0e2b39d6a0b4e7def15c7d1d73973bf944
Reporting entity
- Name
- Builders Insurance (A Mutual Captive Company)norm: builders insurance a mutual captive
Victim entity
- Name
- Builders Insurance (A Mutual Captive Company)norm: builders insurance a mutual captive
Incident
- Discovered
- Dec 14, 2022
- Materiality determined
- —
- Notification sent
- Sep 29, 2023
- Affected individuals
- 7
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- providing written notice of this incident to relevant state regulators, as necessary, and to the three major credit reporting agencies, Equifax, Experian, and TransUnion
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 41 weeks(289 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.