Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Springfield Armory
bd_8aca0c9b10219526 · schema v1 · pii pii-v1
Full breach record for Springfield Armory →Springfield Hospital notified the New Hampshire Attorney General on April 10, 2026, regarding unauthorized access to an employee email account on December 17, 2025. The incident affected 806 New Hampshire residents, exposing names, dates of birth, treatment reasons, and medical record numbers. The hospital secured the email tenant, investigated, and provided written notices with credit monitoring resources to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed806 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/springfield-hospital-20260414.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 14, 2026
- Raw hash
- ed245dbaa56f4f819783699d3a12ff911ac819f0eefa7b6a41a3e8c780b63852
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- Springfield Armorynorm: springfield armory
- Domain
- springfield-armory.com
Incident
- Discovered
- Feb 10, 2026
- Materiality determined
- —
- Notification sent
- Apr 10, 2026
- Affected individuals
- 806
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(63 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.