HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
U.S. 1031 Exchange Services. Inc.
bd_af10ef47e2dbedc9 · schema v1 · pii pii-v1
Full breach record for U.S. 1031 Exchange Services. Inc. →Supplemental notice from U.S. 1031 Exchange Services, Inc. regarding a cybersecurity incident first discovered on October 16, 2025. Unauthorized access compromised names, addresses, SSNs, and bank account/routing numbers for 1,208 individuals, including 4 New Hampshire residents. Response included forensic investigation, password resets, MFA implementation, and 12 months of credit monitoring.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_83579b33e44da3b6Maine State AGfiled 2026-05-08Verified
- bd_861a4533ccb00907Vermont State AGfiled 2026-05-11(3d gap)Verified
- bd_2de9fe731e5d0b51Maine State AGfiled 2026-04-23(15d gap)Candidate
- bd_6bfb2470723c5adaNew Hampshire State AGfiled 2026-04-23(15d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 15d gap
- bd_eeeb90f271235d7fIndiana State AGfiled 2026-04-23(15d gap)Verified
- bd_f3d0dcf027559105Indiana State AGfiled 2026-04-23(15d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/us-1031-exchange-services-20260508.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 8, 2026
- Raw hash
- 3c33557b09ca8def16bc2bac01a56740456308a05e20a565d37da8ba3a38c6e9
Reporting entity
- Name
- Wilson, Elser, Moskowitz, Edelman & Dicker LLPnorm: wilson elser moskowitz edelman dicker
Victim entity
- Name
- U.S. 1031 Exchange Services. Inc.norm: us 1031 exchange
Incident
- Discovered
- Oct 16, 2025
- Materiality determined
- —
- Notification sent
- May 8, 2026
- Affected individuals
- 1,208
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 weeks(204 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.