HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Burney
bd_b7c3a0d67e343e22 · schema v1 · pii pii-v1
Full breach record for Burney →The Burney Company notified the NH Attorney General on July 10, 2025, of a data security incident discovered on May 14, 2025. Unauthorized access to email accounts resulted in altered direct deposits and missed tax refunds for clients. Personal information including names, SSNs, driver's licenses, and bank account numbers was potentially accessed. Approximately 2 NH residents were affected. The company engaged cybersecurity experts, secured systems, and offered 12 months of credit monitoring via TransUnion.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/burney-20250710.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 10, 2025
- Raw hash
- f0087cf73dad3b6ba1f58d66c49dd40ff8a866fecd5d76dd8869dc2168e0bd3f
Reporting entity
- Name
- Burneynorm: burney
- Domain
- burneyssweetsandmore.com
Victim entity
- Name
- Burneynorm: burney
- Domain
- burneyssweetsandmore.com
Incident
- Discovered
- May 14, 2025
- Materiality determined
- Jun 23, 2025
- Notification sent
- Jul 10, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.