HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Sprouse Shrader Smith PLLC
bd_b92a9f24a528a3f1 · schema v1 · pii pii-v1
Full breach record for Sprouse Shrader Smith PLLC →Sprouse Shrader Smith PLLC, a law firm, notified the New Hampshire Attorney General on March 16, 2026, of a cybersecurity incident discovered on February 25, 2025. Unauthorized access resulted in the copying of documents containing personal information, including names, SSNs, driver's licenses, financial account numbers, and medical data. Eight New Hampshire residents were affected. The firm disconnected systems, engaged forensic specialists, reset passwords, and provided 12 months of credit monitoring.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_2eb301f061c7c9c1Indiana State AGfiled 2026-03-10(6d gap)Candidate
- bd_4ef7b13f8d901a9bVermont State AGfiled 2026-03-10(6d gap)Verified
- bd_5de596b35ed93fd5Maine State AGfiled 2026-03-10(6d gap)Verified
- bd_73343a817e875746Indiana State AGfiled 2026-03-10(6d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 50d gap
- bd_03c5059d95a354faNew Hampshire State AGfiled 2026-04-17(32d gap)Verified
- bd_5ccacb39f9b8310fTexas State AGfiled 2026-05-05(50d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sprouse-shrader-smith-20260316.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 16, 2026
- Raw hash
- 6e5a79817732c54ef48eecc710d3e9e1327414475580519bc746cb45a50e3751
Reporting entity
- Name
- Sprouse Shrader Smith PLLCnorm: sprouse shrader smith
Victim entity
- Name
- Sprouse Shrader Smith PLLCnorm: sprouse shrader smith
Incident
- Discovered
- Feb 25, 2025
- Materiality determined
- —
- Notification sent
- Mar 10, 2026
- Affected individuals
- 8
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the FBI and local law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 months(384 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.