HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumActive
Normandin, Cheney & O'Neil PLLC
bd_cf5accc221a3f02c · schema v1 · pii pii-v1
Full breach record for Normandin, Cheney & O'Neil PLLC →Normandin, Cheney & O’Neil, PLLC (NCO) notified the NH Attorney General of a data breach involving unauthorized network access between Dec 20-24, 2025. NCO identified 12 NH residents whose SSN and/or driver's license numbers may have been copied. NCO engaged law enforcement, changed passwords, and provided 12 months of credit monitoring via Cyberscout/TransUnion. Notices began mailing March 11, 2025 (likely typo for 2026 given breach dates).
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed12 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/normandin-cheney-oneil-20260320.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 20, 2026
- Raw hash
- a6414697dd42a025caff50ccb1487461bcbf6947e32ab708f879d07a4bfb376e
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- Normandin, Cheney & O'Neil PLLCnorm: normandin cheney o neil
Incident
- Discovered
- Dec 24, 2025
- Materiality determined
- —
- Notification sent
- Mar 11, 2025
- Affected individuals
- 12
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.