HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Equinavia LLC
bd_abdb4bdd79a217f7 · schema v1 · pii pii-v1
Full breach record for Equinavia LLC →Equinavia, LLC notified the New Hampshire Attorney General of a cybersecurity incident affecting 8 NH residents. An unauthorized actor gained access to Equinavia's e-commerce platform on Feb 9, 2025, and deployed credential-harvesting scripts on the checkout page starting Feb 12, 2025. The scripts harvested names and credit card details (including CVV and expiration). Equinavia discovered the activity on Sept 5, 2025, removed the scripts, and engaged forensic experts. Notifications and credit monitoring were provided to affected individuals starting Nov 4, 2025.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_240ea83c3cb43c40Indiana State AGfiled 2025-11-04(6d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/equinavia-20251110.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 10, 2025
- Raw hash
- 7c827bdfe4f2a82d06ce6a4a191370b86a3a737f753c965a0af62c7723a29b36
Reporting entity
- Name
- McDonaldnorm: mcdonald
- Domain
- mcdonalds-menus.us
Victim entity
- Name
- Equinavia LLCnorm: equinavia
Incident
- Discovered
- Sep 5, 2025
- Materiality determined
- —
- Notification sent
- Nov 4, 2025
- Affected individuals
- 8
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(66 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.