HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
American Association of Critical-Care Nurses
bd_d512ba3bd7ec0b45 · schema v1 · pii pii-v1
Full breach record for American Association of Critical-Care Nurses →American Association of Critical-Care Nurses (AACN) notified the New Hampshire Attorney General on August 29, 2025, of a data security event involving its website's payment system. Unauthorized access to payment card information (card number, expiry, CVV), names, and contact details occurred starting March 8, 2025, and was detected on July 31, 2025. Approximately 309 New Hampshire residents were potentially impacted. AACN secured the payment system, engaged outside security experts, and offered two years of complimentary credit and identity monitoring.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_475370cbda26655dCalifornia State AGfiled 2025-08-29Candidate
- bd_6820d7d37f0ea9fdOregon State AGfiled 2025-08-29Verified
- bd_80f7a1e26b0cb573Indiana State AGfiled 2025-08-29Verified
- bd_d266e08df4700389Montana State AGfiled 2025-08-29Verified
Show 3 more filings ↓Show fewer ↑up to 6d gap
- bd_e05bd527f050d997Maine State AGfiled 2025-08-29Verified
- bd_db08057b57a2ededVermont State AGfiled 2025-09-02(4d gap)Verified
- bd_8242bb219dadeba0Texas State AGfiled 2025-09-04(6d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/american-association-critical-care-nurses-20250829.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2025
- Raw hash
- 5b82ae9fb87533a25bc4bff58dc88713ca1ee7c04ff7b6381f2d5105a5d00bef
Reporting entity
- Name
- HOGAN LOVELLS US LLPnorm: hogan lovells us
Victim entity
- Name
- American Association of Critical-Care Nursesnorm: american association of critical care nurses
- Domain
- aacn.org
Incident
- Discovered
- Jul 31, 2025
- Materiality determined
- —
- Notification sent
- Aug 29, 2025
- Affected individuals
- 309
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.