HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Sellmark Corporation
bd_945f9c63c06c9753 · schema v1 · pii pii-v1
Full breach record for Sellmark Corporation →Sellmark Corporation notified the New Hampshire Attorney General of a cybersecurity incident involving unauthorized access to its network between March 10 and April 14, 2025. The breach affected four New Hampshire residents, exposing names, Social Security numbers, driver's license numbers, and financial account information. Sellmark secured its systems, engaged a cybersecurity firm, reported to law enforcement, and mailed notifications on September 11, 2025, offering one year of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_481c301aa70aed91Maine State AGfiled 2025-09-11Candidate
- bd_4e42db266ced1ff9Indiana State AGfiled 2025-09-11Verified
- bd_68aa45d2d7f88a2aTexas State AGfiled 2025-09-12(1d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sellmark-20250911.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2025
- Raw hash
- aa0aed720405ed0c3f9809e995d299708641a7a3435074f6cf63572d918b0fcb
Reporting entity
- Name
- Sellmark Corporationnorm: sellmark
Victim entity
- Name
- Sellmark Corporationnorm: sellmark
Incident
- Discovered
- Aug 14, 2025
- Materiality determined
- —
- Notification sent
- Sep 11, 2025
- Affected individuals
- 4
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.