DisclosureLens
HackingGovernmentFinancial ServicesGovernmentStolen CredentialsBECTargetedCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Financial accountGovernment IDMediumContained

New Hampshire Retirement System

bd_bcc3e27574422c1b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jul 21, 2017

Filed

Aug 9, 2017

To disclose

19 days

Affected · nationwide

4543 in this filing

Confidence

64%
Full breach record for New Hampshire Retirement System2 incidents on file

New Hampshire Retirement System (NHRS) notified the NH Attorney General on August 9, 2017, of a data security incident affecting 45 retirees. An unauthorized party established fraudulent online accounts in the NHRS 'My Account' portal in early July 2017 to redirect pension payments to Green Dot Bank accounts. NHRS detected the fraud before payments were processed, shutting down the function and deactivating the accounts. Affected data included bank account numbers, names, addresses, DOBs, and last 4 digits of SSNs. No pension funds were lost. NHRS reported to the Secret Service and NH State Police, offered credit monitoring, and implemented stricter authentication controls.

Incident timeline

undetected · 20 days
discovery → filing · 19 days

Jul 1, 2017

Begins

Jul 21, 2017

Discovered

Aug 9, 2017

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed45 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.