HackingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
MERKLE INC
bd_a35e9f4dec1e0522 · schema v1 · pii pii-v1
Full breach record for MERKLE INC →Merkle Inc. notified the New Hampshire Attorney General of a security incident affecting one NH resident. Unauthorized access to Merkle's servers resulted in the exfiltration of names and Social Security numbers. The breach was detected on August 31, 2025, and notification was mailed on February 6, 2026. Merkle engaged a cybersecurity firm, contained the activity, and provided one year of credit monitoring to the affected individual.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/merkle-20260206.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 6, 2026
- Raw hash
- b4393e3d0983edd3944800449029a31864c35183776ddcea9aebac609862d483
Reporting entity
- Name
- MERKLE INCnorm: merkle
Victim entity
- Name
- MERKLE INCnorm: merkle
Incident
- Discovered
- Aug 31, 2025
- Materiality determined
- —
- Notification sent
- Feb 6, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 weeks(159 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.