HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
McLaughlin & Stern LLP
bd_cfaaaf758e7fdb2b · schema v1 · pii pii-v1
Full breach record for McLaughlin & Stern LLP →McLaughlin & Stern, LLP reported that on or about April 7, 2025, an unknown actor copied and/or downloaded data containing names and Social Security numbers. The firm engaged third-party specialists to investigate, confirmed network security, and identified 7 affected New Hampshire residents. Notifications were sent on July 3, 2025, offering credit monitoring services.
Leak gap clock⏱ Leak >30d12 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
A leak claim by silentransomgroup about this victim predates this filing by 88 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_a13ed0fa91e417d6Leak Sitesilentransomgroupfiled 2025-04-05(89d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_2f536740152c6beaMaine State AGfiled 2025-07-03Verified
- bd_4248a16a41f158e7Vermont State AGfiled 2025-07-03Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mclaughlin-stern-20250703.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 3, 2025
- Raw hash
- f4c56a3e2d2f7b41823bacf7af61b09129f4499d4aa023e9e6f535b6c43ea44f
Reporting entity
- Name
- McLaughlin & Stern LLPnorm: mclaughlin stern
- Domain
- mclaughlinstern.com
Victim entity
- Name
- McLaughlin & Stern LLPnorm: mclaughlin stern
- Domain
- mclaughlinstern.com
Incident
- Discovered
- Apr 7, 2025
- Materiality determined
- Jun 3, 2025
- Notification sent
- Jul 3, 2025
- Affected individuals
- 7
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General Consumer Protection Bureau
Compliance
- Time to disclose
- 12 weeks(87 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.