Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Sterling
bd_a2bac98dc6f5e945 · schema v1 · pii pii-v1
Full breach record for Sterling →Sterling Seacrest Pritchard, Inc. (SSP), an insurance brokerage, notified the New Hampshire Attorney General of a data security incident affecting 14 NH residents. SSP discovered suspicious email activity on August 13, 2025, involving unauthorized access between August 12-13, 2025. Personal information, including names and Social Security Numbers, was potentially compromised. SSP engaged independent experts, secured the email environment, and offered 12 months of credit monitoring and identity protection services via Kroll to affected individuals.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_3be48f35f380de72Indiana State AGfiled 2026-03-25(2d gap)Candidate
- bd_d3c3d7329b967472Indiana State AGfiled 2026-03-25(2d gap)Candidate
- bd_61b6c7f9d335b96bNew Hampshire State AGfiled 2026-05-19(53d gap)Verified
- bd_ba9145ecccf11312Maine State AGfiled 2026-05-21(55d gap)Verified by operator
Show 1 more filing ↓Show fewer ↑up to 82d gap
- bd_5d155bf5e75159b1New Hampshire State AGfiled 2026-06-17(82d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sterling-seacrest-pritchard-20260327.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2026
- Raw hash
- ba559548e8a88bf3749ecd3ca39eccfb99d761cd5e5812441bc5493d2e356689
Reporting entity
- Name
- Sterlingnorm: sterling
- Domain
- sterling.com
Victim entity
- Name
- Sterlingnorm: sterling
- Domain
- sterling.com
Incident
- Discovered
- Aug 13, 2025
- Materiality determined
- —
- Notification sent
- Mar 25, 2026
- Affected individuals
- 14
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 32 weeks(226 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.