HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Children's Council of San Francisco
bd_d544b6922b9ab320 · schema v1 · pii pii-v1
Full breach record for Children's Council of San Francisco →Children’s Council of San Francisco, a California non-profit, notified the New Hampshire Attorney General of a data security incident affecting one NH resident. Unauthorized access occurred on or about August 1, 2025, involving the resident's name and Social Security Number. The Council engaged cybersecurity experts, reported the incident to the FBI, and sent notification letters offering 12 months of credit monitoring and identity theft protection services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_13cc3591bebd9bb2Maine State AGfiled 2026-03-03Verified by operator
- bd_ac66c0f72cc2eaf3Vermont State AGfiled 2026-03-03Verified
- bd_f70372d1a991c750California State AGfiled 2026-02-27(4d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/childrens-council-san-francisco-20260303.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 3, 2026
- Raw hash
- 1b09f220015c4929832630440d0973e9d55f73b5e62849b39a86520e73f8ff4a
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Children's Council of San Francisconorm: children s council of san francisco
Incident
- Discovered
- Aug 3, 2025
- Materiality determined
- —
- Notification sent
- Mar 2, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 30 weeks(212 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.