MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Harwood Lloyd, LLP
bd_c5f8c1c7c64405c2 · schema v1 · pii pii-v1
Full breach record for Harwood Lloyd, LLP →Harwood Lloyd, LLP notified the New Hampshire Attorney General of a cybersecurity incident involving one New Hampshire resident. The breach occurred between April 16-21, 2023, when an unauthorized third party accessed systems and encrypted files (ransomware). The firm discovered the encryption on April 20, 2023, and confirmed personal information was involved on October 10, 2023. Notifications were mailed on October 29, 2024, offering credit monitoring. The firm engaged forensic investigators and law enforcement.
Leak gap clock✗ Leak >180d19 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by lockbit_3 about this victim predates this filing by 522 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_402c63010edc4ad5Montana State AGfiled 2024-11-05Candidate
- bd_95fcfcaf4185dc59Maine State AGfiled 2024-11-05Verified by operator
- bd_c7f3e64cbd0ab20fVermont State AGfiled 2024-11-05Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/harwood-lloyd-20241105.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 5, 2024
- Raw hash
- c5d5ba511b3da87a1a656898cf76d939f6a7a6999a91c76dc2caeeb0130d0e75
Reporting entity
- Name
- Harwood Lloyd, LLPnorm: harwood lloyd
- Domain
- harwoodlloyd.com
Victim entity
- Name
- Harwood Lloyd, LLPnorm: harwood lloyd
- Domain
- harwoodlloyd.com
Incident
- Discovered
- Apr 20, 2023
- Materiality determined
- —
- Notification sent
- Oct 29, 2024
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
Compliance
- Time to disclose
- 19 months(565 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.