HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_GOVERNMENTIDENTITY_BASICMediumActive
The LoveSac Company
bd_bedf34d850941636 · schema v1 · pii pii-v1
Full breach record for The LoveSac Company →The LoveSac Company notified the New Hampshire Attorney General of a data event affecting 12 state residents. Between May 27 and May 30, 2025, an unauthorized actor accessed one employee's email account, potentially exposing names and Social Security numbers. LoveSac discovered the suspicious activity on May 30, 2025, and provided notices to affected residents on September 4, 2025. Response measures included 24 months of complimentary credit monitoring via Experian and enhanced employee safeguards.
Leak gap clock✗ Leak >180d14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
A leak claim by ransomhub about this victim predates this filing by 188 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_2ab4dbfe2f4645b5Indiana State AGfiled 2025-09-04Candidate
- bd_55ce6f94b7259130Indiana State AGfiled 2025-09-04Verified
- bd_5ab5de4fec271deeMaine State AGfiled 2025-09-04Candidate
- bd_81c14587331502c2Maine State AGfiled 2025-09-04Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_8f82ad1bad5501b1Vermont State AGfiled 2025-09-04Verified
- bd_a32eb25ec7419355New Hampshire State AGfiled 2025-09-05(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lovesac-20250904.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 4, 2025
- Raw hash
- 6d8f505cd2f05479ee3880d800748e7eefff781756901524a7880da984e85c4c
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- The LoveSac Companynorm: the lovesac
- Domain
- lovesac.com
Incident
- Discovered
- May 30, 2025
- Materiality determined
- —
- Notification sent
- Sep 4, 2025
- Affected individuals
- 12
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Provided written notice of this incident to relevant state regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(97 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.