HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Keystone Shipping
bd_dcd977c2ac04ab21 · schema v1 · pii pii-v1
Full breach record for Keystone Shipping →Keystone Shipping Co. notified the New Hampshire Attorney General of unauthorized network access on June 3, 2025. The incident exposed names and Social Security numbers of 4 NH residents. Keystone engaged external cybersecurity firms, reported to law enforcement, and sent notifications on July 21, 2025, offering one year of credit monitoring.
Leak gap clock⏱ Leak >30d7 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
A leak claim by akira about this victim predates this filing by 50 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_689cba8dfad9bdc9Leak Siteakirafiled 2025-06-03(49d gap)Verified
- bd_5e4fb85292529934Leak Siteakirafiled 2025-06-02(50d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_283c7580fdfecbe1Maine State AGfiled 2025-07-22Verified
- bd_072c1e4c8bf85c42Indiana State AGfiled 2025-07-21(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/keystone-shipping-20250722.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2025
- Raw hash
- 60586d0d9d28b728ba520117c5122de7b8867d63394372567971dd500b6d4365
Reporting entity
- Name
- Keystone Shippingnorm: keystone shipping
- Domain
- keyship.com
Victim entity
- Name
- Keystone Shippingnorm: keystone shipping
- Domain
- keyship.com
Incident
- Discovered
- Jun 3, 2025
- Materiality determined
- Jun 20, 2025
- Notification sent
- Jul 21, 2025
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.