DisclosureLens
MalwareProfessional ServicesProfessional ServicesRansomwareData ExfiltratedRansom DemandedCustomer Data InvolvedGovernment IDIdentity (basic)MediumContained

Payne and Fears LLP

bd_a73c76c399836f3c · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 8, 2021

Filed

Apr 30, 2021

To disclose

8 weeks

Affected

1state residents only

Linked

4 filings

Confidence

67%
Full breach record for Payne and Fears LLP

Payne and Fears, LLP, a law firm, notified the New Hampshire Attorney General of a ransomware attack discovered on March 8, 2021. The incident resulted in unauthorized access to the network and the potential exfiltration of one New Hampshire resident's personal information, including a Social Security number and passport number. The firm engaged forensic experts and the FBI, and provided the affected individual with 12 months of credit monitoring through Experian. Notification to the AG was filed on April 30, 2021.

Incident timeline

discovery → filing · 8 weeks / 53 days

Mar 8, 2021

Discovered

Apr 30, 2021

Filed

vs. sector median

11 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Maine State AGApr 21 · first
New Hampshire State AG+9d · this page

Pattern: first filing Apr 21 (ME), last Apr 30 (NH) — a 9-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.