HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Champion Healthcare
bd_bfec1c97d3903a28 · schema v1 · pii pii-v1
Full breach record for Champion Healthcare →Champion Manufacturing, Inc. dba Champion Healthcare notified Massachusetts residents of a cybersecurity incident detected in late January 2026. An unauthorized party accessed internal corporate systems and obtained files containing personal information, including names and government identifiers. The company engaged third-party cybersecurity experts, reviewed affected files, and offered 24 months of complimentary credit monitoring via Experian IdentityWorks.
Massachusetts clock⏱ MA AG >30d13 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_331b80f1be2b23dcNew Hampshire State AGfiled 2026-05-08(7d gap)Verified
- bd_cc0f5c1b1d824494Indiana State AGfiled 2026-05-08(7d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-735-champion-manufacturing-inc-dba-champion-healthcare/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- 4339e2bfbd56035b5396e0834f021d325468252e41a786f0c01b938e50d820b5
Reporting entity
- Name
- Champion Healthcarenorm: champion healthcare
- Domain
- champion-healthcare.com
Victim entity
- Name
- Champion Healthcarenorm: champion healthcare
- Domain
- champion-healthcare.com
Incident
- Discovered
- Jan 31, 2026
- Materiality determined
- —
- Notification sent
- May 8, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(90 days from discovery to filing)
- Compliance flags
- MA AG >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.