HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Legend Senior Living, LLC
bd_9eb6e7a4c7d5c659 · schema v1 · pii pii-v1
Full breach record for Legend Senior Living, LLC →Legend Senior Living LLC notified the New Hampshire Attorney General of a data event affecting 4 NH residents. Unauthorized access occurred between July 27, 2025, and August 15, 2025. Affected data included names, SSNs, and driver's license numbers. Legend notified law enforcement, provided 12 months of credit monitoring via TransUnion/Cyberscout, and sent notices on April 10, 2026.
Leak gap clock✗ Leak >180d37 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4 affectedView incident
A leak claim by worldleaks about this victim predates this filing by 255 days.View originating leak claim
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/legend-senior-living-20260410.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 10, 2026
- Raw hash
- e78b6187eabd612b83f1d87b871c758b95210013b95b6d0d8fcf82194f306adb
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Legend Senior Living, LLCnorm: legend senior living
- Domain
- legendseniorliving.com
Incident
- Discovered
- Jul 27, 2025
- Materiality determined
- —
- Notification sent
- Apr 10, 2026
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement and relevant regulatory agenciesproviding written notice of this incident to relevant state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 37 weeks(257 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.