HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Jeff Anderson & Associates PA
bd_91b364a07fe72e9c · schema v1 · pii pii-v1
Full breach record for Jeff Anderson & Associates PA →Jeff Anderson & Associates PA (JAA) notified the New Hampshire Attorney General of a data event affecting one NH resident. Unauthorized access occurred on September 18, 2025, involving the copying of data including names, SSNs, DOBs, and medical info. JAA engaged third-party specialists, notified law enforcement, and provided 24 months of credit monitoring via Experian to the affected individual. The investigation concluded on December 8, 2025, with notification sent on December 19, 2025.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_17b24dde1fc4edb5Indiana State AGfiled 2025-12-19Candidate
- bd_4d61d64c2f99c415California State AGfiled 2026-02-10(53d gap)Verified
- bd_116d30fdd32f2efdCalifornia State AGfiled 2026-02-26(69d gap)Verified
- bd_685ea336212807caVermont State AGfiled 2026-02-26(69d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/jeff-anderson-associates-20251219.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2025
- Raw hash
- 65c37891a009aab13ef4513424891bd7d78389c451dc66f2d0eed34b06511585
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Jeff Anderson & Associates PAnorm: jeff anderson associates
- Domain
- andersonsadvocates.com
Incident
- Discovered
- Sep 18, 2025
- Materiality determined
- —
- Notification sent
- Dec 19, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement regarding the eventproviding written notice of this incident to relevant state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(92 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.