HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICHighContained
Riddell Law Group
bd_b2ec90e94e2bb110 · schema v1 · pii pii-v1
Full breach record for Riddell Law Group →Riddell Law Group experienced unauthorized access to its network on October 16, 2025, resulting in the exposure of client PII, including SSNs, financial account numbers, and health information. The breach affected 19,596 individuals, including 87 New Hampshire residents. Riddell engaged forensic investigators, shut down workstations, reset passwords, implemented MFA, and offered 12 months of credit monitoring. Notification letters were mailed on February 12, 2026.
Leak gap clock⏱ Leak >90d17 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by pear about this victim predates this filing by 120 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_f3b46a9bcd2bee5fLeak Sitepearfiled 2025-10-15(120d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_05769817e513158dIndiana State AGfiled 2026-02-12Candidate
- bd_8089adb8730c386fIndiana State AGfiled 2026-02-12Verified by operator
- bd_c2b6ab2133992b76Maine State AGfiled 2026-02-12Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/riddell-law-group-20260212.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 12, 2026
- Raw hash
- 7116b65168732f0cab4f46c4e293dae3a6070dd9ba0c3b0ba0f945017b6763d8
Reporting entity
- Name
- Wilson, Elser, Moskowitz, Edelman & Dicker LLPnorm: wilson elser moskowitz edelman dicker
Victim entity
- Name
- Riddell Law Groupnorm: riddell law
- Domain
- rlglawfirm.com
Incident
- Discovered
- Oct 16, 2025
- Materiality determined
- —
- Notification sent
- Feb 12, 2026
- Affected individuals
- 19,596
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 weeks(119 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.