HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Catholic Charities of the Diocese of Albany
bd_98acff8a64d949ef · schema v1 · pii pii-v1
Full breach record for Catholic Charities of the Diocese of Albany →Catholic Charities of the Diocese of Albany notified the New Hampshire Attorney General of a data breach involving unauthorized network access between March 29 and July 31, 2025. The incident was discovered on July 30, 2025, and affected approximately one New Hampshire resident, whose name and Social Security number were compromised. The organization reset passwords, engaged forensic investigation, notified law enforcement, and provided one year of complimentary credit monitoring services to the affected individual.
Leak gap clock✗ Leak >180d18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by pear about this victim predates this filing by 199 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_c69e641d8bcc0ecbVermont State AGfiled 2025-11-26(5d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/catholic-charities-diocese-albany-20251201.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 1, 2025
- Raw hash
- 4758ec4e93be6fc487cbc48c9191e5c50b0ea1c76c9bbfa840ac8532d86fb389
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- Catholic Charities of the Diocese of Albanynorm: catholic charities of the diocese of albany
- Domain
- ccrcda.org
Incident
- Discovered
- Jul 30, 2025
- Materiality determined
- —
- Notification sent
- Nov 24, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 weeks(124 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.