HackingStolen CredentialsData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CNHI, LLC
bd_bad5e82d02c73257 · schema v1 · pii pii-v1
Full breach record for CNHI, LLC →CNHI, LLC notified South Carolina AG of unauthorized network access between April 27 and May 17, 2025. Files containing names and Social Security numbers were taken. CNHI secured the network, investigated, and engaged Experian to provide one-year identity protection services. Security protocols were enhanced. No specific count of affected individuals was disclosed in the filing.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_51267646cce26e95Indiana State AGfiled 2025-12-08Verified
- bd_5c40821d85f38cedNew Hampshire State AGfiled 2025-12-08Verified
- bd_636302d394e1cd30Vermont State AGfiled 2025-12-08Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Consumer%20Letter%20-%20CNHI%2C%20LLC.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 8, 2025
- Raw hash
- 4b49aeec20ab0e8d57bf4c47f17edc12ece319b67c6085f138508ae907497612
Reporting entity
- Name
- CNHI, LLCnorm: cnhi
Victim entity
- Name
- CNHI, LLCnorm: cnhi
Incident
- Discovered
- Apr 27, 2025
- Materiality determined
- —
- Notification sent
- Dec 8, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 32 weeks(225 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.