HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Caldwell Bank & Trust Company
bd_d65d44a19606a1fb · schema v1 · pii pii-v1
Full breach record for Caldwell Bank & Trust Company →Caldwell Trust Company notified the New Hampshire Attorney General of a cybersecurity incident involving unauthorized access to its network between August 4 and August 8, 2025. The investigation determined that an unauthorized actor accessed files containing names and financial account numbers for two New Hampshire residents. Notification letters were sent on September 23, 2025. Caldwell notified law enforcement, secured its network, and enhanced security protocols.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_14983cf9d464380cIndiana State AGfiled 2025-09-23Verified
- bd_6de67cfcf08d8223Vermont State AGfiled 2025-09-23Verified
- bd_f4ce5ece45ee771eMaine State AGfiled 2025-09-23Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/caldwell-trust-20250923.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 23, 2025
- Raw hash
- a17d505bb5f25fa21894e51ccdfc42206978d2b78523b199c76c045034945d78
Reporting entity
- Name
- Caldwell Bank & Trust Companynorm: caldwell bank
Victim entity
- Name
- Caldwell Bank & Trust Companynorm: caldwell bank
Incident
- Discovered
- Sep 4, 2025
- Materiality determined
- —
- Notification sent
- Sep 23, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 19 days(19 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.