HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
HydroServe LLC
bd_8fbbdf74570d3bbb · schema v1 · pii pii-v1
Full breach record for HydroServe LLC →HydroServe LLC (dba Gustavo Preston Company) notified the New Hampshire Attorney General on December 19, 2025, of a data event affecting 41 NH residents. Unauthorized access occurred between October 6 and October 14, 2025, involving the viewing or downloading of names, government IDs, SSNs, and medical information. The company provided 12 months of credit monitoring via IDX and implemented additional safeguards.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_cad7970b8aa13558Indiana State AGfiled 2025-12-19Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/hydroserve-20251219.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2025
- Raw hash
- 1648fc7ad413fcb5fea06c19c47dd234d4194ed404c6b6303cd3889c5a6d9dbb
Reporting entity
- Name
- HydroServe LLCnorm: hydroserve
Victim entity
- Name
- HydroServe LLCnorm: hydroserve
Incident
- Discovered
- Oct 14, 2025
- Materiality determined
- —
- Notification sent
- Dec 19, 2025
- Affected individuals
- 41
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(66 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.