HackingIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
American Israel Public Affairs Committee
bd_b16afa675d2f33ec · schema v1 · pii pii-v1
Full breach record for American Israel Public Affairs Committee →American Israel Public Affairs Committee (AIPAC) notified the New Hampshire Attorney General of a cyberattack affecting one NH resident. Unauthorized access occurred between October 20, 2024, and February 6, 2025. AIPAC determined on August 28, 2025, that PII (names, SSNs, driver's licenses, financial/health data) was accessed. AIPAC engaged third-party experts, upgraded security controls, and provided 12 months of credit monitoring to the affected individual.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2b0b5d28ded09d18Indiana State AGfiled 2025-11-13Verified
- bd_8d856154b6fbab42Montana State AGfiled 2025-11-13Candidate
- bd_45c00ab8cbd814e7Maine State AGfiled 2025-11-14(1d gap)Candidate
- bd_9382bcc830c0df45Maine State AGfiled 2025-11-17(4d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/american-israel-public-affairs-committee-20251113.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 17459ef66cd005995d334fe8e84afd23388b869179765c0e024d51f8104ef18e
Reporting entity
- Name
- Jackson Lewisnorm: jackson lewis
- Domain
- jacksonlewis.com
Victim entity
- Name
- American Israel Public Affairs Committeenorm: american israel public affairs committee
Incident
- Discovered
- Aug 28, 2025
- Materiality determined
- —
- Notification sent
- Nov 13, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection and Antitrust Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(77 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.