MalwarePhishingRansomwareData EncryptedRansom DemandedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
The Christian Brothers Academy of Albany
bd_b1727c63ed6eb770 · schema v1 · pii pii-v1
Full breach record for The Christian Brothers Academy of Albany →Christian Brothers Academy notified the New Hampshire Attorney General of a cybersecurity incident affecting two NH residents. Unauthorized actors gained access via a phishing attack, launching a ransomware attack. CBA secured systems, did not pay ransom, and engaged forensic investigators. Affected data may include names, addresses, financial info, driver's licenses, and passports. Notifications were mailed on August 15, 2025, offering two years of credit monitoring.
Leak gap clock⏱ Leak >30d10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
A leak claim by interlock about this victim predates this filing by 63 days.View originating leak claim
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/christian-brothers-academy-20250815.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 15, 2025
- Raw hash
- 3a19daf9f03548be456c206c8127e6d462da379bb1904425289173f99adef509
Reporting entity
- Name
- The Christian Brothers Academy of Albanynorm: the christian brothers academy of albany
Victim entity
- Name
- The Christian Brothers Academy of Albanynorm: the christian brothers academy of albany
Incident
- Discovered
- Jun 4, 2025
- Materiality determined
- —
- Notification sent
- Aug 15, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- phishing_link
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.