HackingVulnerability ExploitStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
DecisionDesk, Inc.
bd_b39406ddea3c7aa7 · schema v1 · pii pii-v1
Full breach record for DecisionDesk, Inc. →Decisionfi LLC notified New Hampshire residents of a data breach occurring on or around January 15, 2025. An unknown actor accessed files via the web application. Personal information, including government IDs, was involved. Decisionfi engaged third-party cybersecurity specialists, secured the application, and notified federal law enforcement. Affected individuals are offered credit monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_36f843a5fae646c8Maryland State AGfiled 2025-02-21Candidate
- bd_9e373c38bbbc7ce5Indiana State AGfiled 2025-02-21Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/decisionfi-20250221.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 21, 2025
- Raw hash
- dba7bde258a36a82410e406facab30afdd3126360eb3e5f7a3829c80405f5a96
Reporting entity
- Name
- DecisionDesk, Inc.norm: decisiondesk
Victim entity
- Name
- DecisionDesk, Inc.norm: decisiondesk
Incident
- Discovered
- Jan 15, 2025
- Materiality determined
- Jan 28, 2025
- Notification sent
- Feb 21, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement regarding the event
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.