HackingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
Complete Payroll Solutions
bd_c06fe742fa395840 · schema v1 · pii pii-v1
Full breach record for Complete Payroll Solutions →Complete Payroll Solutions, LLC (CPS) issued a supplemental notice to the New Hampshire Attorney General regarding a data event affecting 21,963 NH residents. On or around March 10, 2024, CPS identified suspicious activity indicating an unauthorized individual accessed systems. CPS reset passwords, engaged law enforcement, and provided credit monitoring via Kroll. The notice supplements an October 2024 filing.
Leak gap clock✗ Leak >180d14 months discovery → filing
This filing is one of 4 about the same incident.View merged incident
A leak claim by meow about this victim predates this filing by 241 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_b49242977c3bd20eIndiana State AGfiled 2025-04-25Verified
- bd_f99beb53f694daceVermont State AGfiled 2025-04-25Candidate
- bd_5fdc02e392c3d7f2New Hampshire State AGfiled 2025-05-28(33d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/complete-payroll-solutions-20250425.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 25, 2025
- Raw hash
- ef0ad8ef353bfef3d031881ca1bbe0963a228729b49b73c311aacefb0d7ac47b
Reporting entity
- Name
- Complete Payroll Solutionsnorm: complete payroll
- Domain
- completepayrollsolutions.com
Victim entity
- Name
- Complete Payroll Solutionsnorm: complete payroll
- Domain
- completepayrollsolutions.com
Incident
- Discovered
- Mar 10, 2024
- Materiality determined
- —
- Notification sent
- Apr 25, 2025
- Affected individuals
- 21,963
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement regarding the eventProviding written notice of this incident to relevant state regulators, as necessary, and to the three major credit reporting agencies, Equifax, Experian, and TransUnion
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 months(411 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.