HackingCustomer Data InvolvedPIIIDENTITY_BASICLowActive
CMC Design-Build
bd_9e29b8479aa87782 · schema v1 · pii pii-v1
Full breach record for CMC Design-Build →CMC Design Build Inc. notified the NH AG of unauthorized access to computerized platforms between Jan 15 and Mar 26, 2025. Suspicious activity was detected on Mar 25, 2025. The investigation is ongoing. One NH resident's PII was potentially involved. CMC engaged third-party cybersecurity specialists and is offering Experian IdentityWorks.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cmc-design-build-20250422.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 22, 2025
- Raw hash
- 2edf9797d137a44d7c9b6e7a1e6d70abd414e5fd0848bb26be78eabd0251df16
Reporting entity
- Name
- CMC Design-Buildnorm: cmc design build
- Domain
- cmcdesignbuild.com
Victim entity
- Name
- CMC Design-Buildnorm: cmc design build
- Domain
- cmcdesignbuild.com
Incident
- Discovered
- Mar 25, 2025
- Materiality determined
- —
- Notification sent
- Apr 22, 2025
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.