DisclosureLens
HackingProfessional ServicesProfessional ServicesStolen CredentialsCustomer Data InvolvedTargetedIdentity (basic)Government IDFinancial accountMediumContained

Burney

bd_b7c3a0d67e343e22 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 14, 2025

Filed

Jul 10, 2025

To disclose

8 weeks

Affected

2state residents only

Linked

2 filings

Confidence

66%
Full breach record for Burney

The Burney Company notified the NH Attorney General on July 10, 2025, of a data security incident discovered on May 14, 2025. Unauthorized access to email accounts resulted in altered direct deposits and missed tax refunds for clients. Personal information including names, SSNs, driver's licenses, and bank account numbers was potentially accessed. Approximately 2 NH residents were affected. The company engaged cybersecurity experts, secured systems, and offered 12 months of credit monitoring via TransUnion.

Incident timeline

discovery → filing · 8 weeks / 57 days

May 14, 2025

Discovered

Jun 23, 2025

Scope determined

Jul 10, 2025

Filed

vs. sector median

10 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
New Hampshire State AGJul 10 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.