CHP 11-99 Foundation
bd_abf1655a014ba033 · schema v1 · pii pii-v1
Full breach record for CHP 11-99 Foundation →2 incidents on fileCHP 11-99 Foundation experienced a data breach after a staff member clicked a malicious link in a phishing email on September 16, 2025, despite initial clearance from a third-party help desk. The attacker gained access to the staff member's email account, potentially exposing membership applications, payment forms, bank/credit card info, SSNs, and driver's license numbers. The incident was discovered on September 24, 2025, when the attacker attempted to phish the help desk. The organization has implemented MFA, changed passwords, and engaged an incident response vendor. Identity monitoring services are being provided to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 16, 2025
Begins
Sep 24, 2025
Discovered
Jan 23, 2026
Filed
vs. sector median
+9 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- New Hampshire State AGbd_8968a5af3b4076c42026-01-20 · +3dVerified
- Massachusetts State AGbd_b56890b11d4ca9ba2026-02-03 · +11dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Jan 20 (NH), last Feb 3 (MA) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.