MalwareRansomwareData EncryptedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumActive
Legacy 5 Corporate Services, LLC
bd_dc03ddbe7c9be58f · schema v1 · pii pii-v1
Full breach record for Legacy 5 Corporate Services, LLC →Legacy 5 Corporate Services, LLC reported a ransomware incident discovered on September 15, 2025, where an external actor encrypted data on an archival hard drive after gaining unauthorized network access. One New Hampshire resident (employee) was affected. Data at risk included names, SSNs, DOBs, addresses, and financial account info. The company engaged forensic investigators, secured the network, and coordinated with law enforcement.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3672ac509edbfe10Vermont State AGfiled 2025-10-10(4d gap)Verified
- bd_9a3a8f3530955d2aIndiana State AGfiled 2025-10-10(4d gap)Verified
- bd_a4ad8b8312413d64Maine State AGfiled 2025-10-09(5d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/legacy-5-corporate-20251014.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 14, 2025
- Raw hash
- 4652d0a2559c524f37f06ad47145f9a554149dbfd8cd35e198dd2f3f9d50d206
Reporting entity
- Name
- TAFT STETTINIUS & HOLLISTER LLPnorm: taft stettinius hollister
Victim entity
- Name
- Legacy 5 Corporate Services, LLCnorm: legacy 5 corporate
Incident
- Discovered
- Sep 15, 2025
- Materiality determined
- —
- Notification sent
- Oct 10, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Consumer Protection & Antitrust Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.