Bansley and Kiener, LLP
bd_911585320be84e19 · schema v1 · pii pii-v1
Full breach record for Bansley and Kiener, LLP →Bansley and Kiener, L.L.P. notified the New Hampshire Attorney General of a cybersecurity incident involving unauthorized access to its systems between August 20 and December 1, 2020. The breach resulted in the encryption of systems (ransomware) and subsequent exfiltration of personal information, including names and Social Security numbers, of 50 New Hampshire residents. The firm discovered the initial encryption on December 10, 2020, and learned of the exfiltration on May 24, 2021. Notifications were mailed on November 30, 2021, offering one year of credit monitoring via Kroll.
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_77b244465609bf86Montana State AGfiled 2021-11-30Verified
- bd_d4aad3f142f6fe81Maine State AGfiled 2021-11-30Verified
- bd_d8742baa54ae80c0California State AGfiled 2021-11-30Verified
- bd_4bae8a61184e543cHHS OCRfiled 2021-12-03(3d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 3d gap
- bd_604e6a41f2e4e972HHS OCRfiled 2021-12-03(3d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/bansley-kiener-20211130.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 30, 2021
- Raw hash
- c4d4876145bdbc06db39e15082cacc563280fc57ddee9c8967910ff9bb98dec5
Reporting entity
- Name
- Bansley and Kiener, LLPnorm: bansley and kiener
- Domain
- bk-cpa.com
Victim entity
- Name
- Bansley and Kiener, LLPnorm: bansley and kiener
- Domain
- bk-cpa.com
Incident
- Discovered
- Dec 10, 2020
- Materiality determined
- —
- Notification sent
- Nov 30, 2021
- Affected individuals
- 50
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified Attorney General John Formella
Compliance
- Time to disclose
- 51 weeks(355 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.