HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Pease Mountain Law, PLLC
bd_aec01e6c3a80164a · schema v1 · pii pii-v1
Full breach record for Pease Mountain Law, PLLC →Pease Mountain Law, PLLC notified the New Hampshire Attorney General of a data event affecting 8 NH residents. An unknown actor accessed an employee's email account between July 21-29, 2025. Potentially compromised data included names, SSNs, driver's license numbers, financial account info, and medical info. Pease Mountain secured the account, engaged third-party specialists, and provided 12 months of credit monitoring via TransUnion. Notification was sent on May 20, 2026.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_2f2c419d11ed8962Maine State AGfiled 2026-05-20Verified by operator
- bd_f61105e35230f361Vermont State AGfiled 2026-05-20Verified
- bd_db5ee62b7f29db4fMassachusetts State AGfiled 2026-05-01(19d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pease-mountain-law-20260520.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 20, 2026
- Raw hash
- 4897d7e57138452bcddb9d3b5edb1adbcc3f381279d903072cedcd095bfd6643
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Pease Mountain Law, PLLCnorm: pease mountain law
- Domain
- peasemountainlaw.com
Incident
- Discovered
- Jul 21, 2025
- Materiality determined
- —
- Notification sent
- May 20, 2026
- Affected individuals
- 8
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified the Office of the New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 43 weeks(303 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.