HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Joyal Capital Management, LLC
bd_b7d127ba290b1f3e · schema v1 · pii pii-v1
Full breach record for Joyal Capital Management, LLC →Joyal Capital Management, LLC reported a data security event affecting approximately 45 New Hampshire residents. The incident, occurring around January 27, 2026, involved unauthorized acquisition of personal information, including names combined with Social Security numbers, driver's license numbers, and financial account information. JCM engaged cybersecurity specialists, notified the FBI, and offered 12 months of complimentary credit monitoring through Kroll.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6c4a3c91bfb39a7dVermont State AGfiled 2026-05-30(5d gap)Verified
- bd_19ace2670edba632Maine State AGfiled 2026-05-29(6d gap)Verified
- bd_783215e35c839a31Indiana State AGfiled 2026-05-29(6d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/joyal-capital-management-20260604.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 4, 2026
- Raw hash
- 22df6281121cb254fe4df7aff3823c5c3e7be9a2ed3d65f83dcc62d3475e1d8b
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Joyal Capital Management, LLCnorm: joyal capital management
- Domain
- joycapmgt.com
Incident
- Discovered
- Jan 27, 2026
- Materiality determined
- —
- Notification sent
- May 29, 2026
- Affected individuals
- 45
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of InvestigationProviding written notice of this incident to relevant regulators, law enforcement and to the three major credit reporting agencies, Equifax, Experian, and TransUnion
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 weeks(128 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.