HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICPHIMediumContained
GORLICK, KRAVITZ & LISTHAUS P.C.
bd_b409c6e8465ab68a · schema v1 · pii pii-v1
Full breach record for GORLICK, KRAVITZ & LISTHAUS P.C. →Gorlick, Kravitz, & Listhaus, P.C. (GKL) notified the New Hampshire Attorney General of a cybersecurity incident affecting approximately one NH resident. Unauthorized access occurred on or around September 30, 2025. GKL discovered personal information (names, SSNs) and PHI was accessed. GKL engaged forensic investigators, offered one year of credit monitoring via Cyberscout, and advised residents on fraud alerts and security freezes. Notification was sent January 2, 2026.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/gorlick-kravitz-listhaus-20260105.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 5, 2026
- Raw hash
- a10ea77ed85a0fc09e31b4a7635629293a1b8c95deb6798947ab9540bd752ddc
Reporting entity
- Name
- McDonaldnorm: mcdonald
- Domain
- mcdonalds-menus.us
Victim entity
- Name
- GORLICK, KRAVITZ & LISTHAUS P.C.norm: gorlick kravitz listhaus
- Domain
- gkllaw.weebly.com
Incident
- Discovered
- Sep 30, 2025
- Materiality determined
- —
- Notification sent
- Jan 2, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(97 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.