HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
APPFOLIO, INC.
bd_bf40a737f4fa3c9a · schema v1 · pii pii-v1
Full breach record for APPFOLIO, INC. →AppFolio, Inc. notified the New Hampshire Attorney General of a third-party data security incident involving its vendor, Salesloft. Unauthorized access to AppFolio's CRM system occurred between August 8-18, 2025. The breach potentially exposed names and Social Security numbers of 231 New Hampshire residents. AppFolio disabled integrations, investigated, and began notifying affected individuals on October 6, 2025, offering one year of credit monitoring.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_0ab3c8362a49414bOregon State AGfiled 2025-10-06Candidate
- bd_2dbe73b43013007fVermont State AGfiled 2025-10-06Verified
- bd_590685df26b700a9Iowa State AGfiled 2025-10-06Verified
- bd_7b911a86227b2297Indiana State AGfiled 2025-10-06Verified
Show 5 more filings ↓Show fewer ↑up to 1d gap
- bd_a9707e98f1214ee6Maine State AGfiled 2025-10-06Verified
- bd_bba06e3c593b96adWashington State AGfiled 2025-10-06Verified
- bd_e971dd45d6d2c1a2California State AGfiled 2025-10-06Verified
- bd_fc212894d34ee2afMontana State AGfiled 2025-10-06Verified
- bd_2b0795c3c4216d87Texas State AGfiled 2025-10-07(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/appfolio-20251006.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 6, 2025
- Raw hash
- 2770239b2b263d8893b685454805227b422d1600ed683a476977058c0f4864c7
Reporting entity
- Name
- APPFOLIO, INC.norm: appfolio
Victim entity
- Name
- APPFOLIO, INC.norm: appfolio
Incident
- Discovered
- Aug 22, 2025
- Materiality determined
- —
- Notification sent
- Oct 6, 2025
- Affected individuals
- 231
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.