Questo, Inc.
bd_b7acf1d77c834d25 · schema v1 · pii pii-v1
Full breach record for Questo, Inc. →Questo, Inc. notified the NH Attorney General of unauthorized access to its network affecting approximately 7 New Hampshire residents. The incident occurred between October 1 and October 9, 2025, and was discovered on October 9, 2025. Affected data includes full names, Social Security numbers, and financial account numbers. Questo contained the incident, engaged outside cybersecurity professionals, and is providing complimentary identity monitoring through Kroll to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 1, 2025
Begins
Oct 9, 2025
Discovered
Jul 23, 2026
Filed
vs. sector median
+22 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Vermont State AGbd_748d4d39d0e167ff2026-07-22 · +1dVerified
- Massachusetts State AGbd_1b7a85c31a3fd63b2026-07-17 · +6dVerified
- Texas State AGbd_6a303fe2629f33262026-07-17 · +6dVerified
- California State AGbd_a5c6ff979e16a9d82026-07-16 · +7dCandidate
Show 1 more filing ↓Show fewer ↑up to 8d gap
- Nebraska State AGbd_0a81a18aa78e777d2026-07-15 · +8dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Jul 15 (NE), last Jul 23 (NH) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.