HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Lgaa LLC
bd_cdcebc4abbb5c612 · schema v1 · pii pii-v1
Full breach record for Lgaa LLC →LGAA LLC notified the New Hampshire Attorney General of a data event affecting approximately 6 state residents. On February 20, 2025, an unknown cyber actor accessed a limited portion of LGAA's network used for data migrations and may have copied files containing names, SSNs, driver's license numbers, and credit/debit card numbers. LGAA investigated, secured the network, removed the data, and provided 12 months of free identity monitoring via TransUnion/Cyberscout to affected individuals. Notification was sent on November 7, 2025.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_17f792c1e981412cIndiana State AGfiled 2025-11-07Verified
- bd_3ea8c2d4373e04d5California State AGfiled 2025-11-07Candidate
- bd_d96ea6f22ebd3215Montana State AGfiled 2025-11-07Verified
- bd_e5190cfed5f21fbbMaine State AGfiled 2025-11-07Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lgaa-20251107.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 7, 2025
- Raw hash
- 3dac34a71a7d034e62f970d0eea30476178cb6dc85df7b22f8392e57fa27a1cf
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Lgaa LLCnorm: lgaa
Incident
- Discovered
- Feb 20, 2025
- Materiality determined
- —
- Notification sent
- Nov 7, 2025
- Affected individuals
- 6
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 37 weeks(260 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.