HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
VacPartsWarehouse.com LLC
bd_7fbc3cbc26c5d303 · schema v1 · pii pii-v1
Full breach record for VacPartsWarehouse.com LLC →VacPartsWarehouse.com LLC notified the New Hampshire Attorney General of a data breach affecting 221 state residents. Unauthorized actors accessed the online shopping platform between October 31 and December 12, 2025, potentially acquiring names, addresses, and payment card details (including CVV). The company discovered the incident on April 22, 2026, and mailed notifications on May 20, 2026. No ransomware or malware was involved; the attack vector appears to be exploitation of the public-facing application.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_53f4c2171b146fc2Oregon State AGfiled 2026-05-20Verified by operator
- bd_66ae80b7d6c35eebIndiana State AGfiled 2026-05-20Verified by operator
- bd_848c508797d33b75California State AGfiled 2026-05-20Verified by operator
- bd_aef6f425d4eac0dbVermont State AGfiled 2026-05-20Verified
Show 3 more filings ↓Show fewer ↑up to 19d gap
- bd_ea2e25270143213eMaine State AGfiled 2026-05-20Verified by operator
- bd_9b74cdc45209ca3bTexas State AGfiled 2026-05-22(2d gap)Verified by operator
- bd_00aed7ea2d6e27e5Massachusetts State AGfiled 2026-05-01(19d gap)Candidate
Source provenance
- Source URL
- https://www.doj.nh.gov/sites/g/files/ehbemt721/files/remote-docs/vacpartswarehouse.com-20260520.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 20, 2026
- Raw hash
- 8a25f5370b0f90dc022b5e043e6657b945a3bf01be6795d94bf4a549714f379c
Reporting entity
- Name
- VacPartsWarehouse.com LLCnorm: vacpartswarehousecom
Victim entity
- Name
- VacPartsWarehouse.com LLCnorm: vacpartswarehousecom
Incident
- Discovered
- Apr 22, 2026
- Materiality determined
- —
- Notification sent
- May 20, 2026
- Affected individuals
- 221
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.