HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Metropolitan Marine Maintenance Contractors' Association, Inc.
bd_de025790cd75f18c · schema v1 · pii pii-v1
Full breach record for Metropolitan Marine Maintenance Contractors' Association, Inc. →Metropolitan Marine Maintenance Contractors' Association (MMMCA) notified the New Hampshire Attorney General of a security incident discovered on April 7, 2026. An unknown threat actor accessed the MMMCA and Metro-ILA Funds' environment via a VPN. The breach impacted 14 New Hampshire residents, exposing names, SSNs, DOBs, and financial account data. MMMCA engaged forensic experts, took the VPN offline, reset passwords, and notified law enforcement and credit bureaus. Affected individuals received 12 months of credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_5a911fe14272f278Vermont State AGfiled 2026-06-18(1d gap)Candidate
- bd_5c0b93e753c3de20Vermont State AGfiled 2026-05-26(22d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/metropolitan-marine-maintenance-contractors-association-20260617.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 17, 2026
- Raw hash
- 28bd3857e86f85aac036cd8919f140418cc6105c5b589b354ac0351dcd939fd4
Reporting entity
- Name
- Metropolitan Marine Maintenance Contractors' Association, Inc.norm: metropolitan marine maintenance contractors
- Domain
- mmmca.org
Victim entity
- Name
- Metropolitan Marine Maintenance Contractors' Association, Inc.norm: metropolitan marine maintenance contractors
- Domain
- mmmca.org
Incident
- Discovered
- Apr 7, 2026
- Materiality determined
- —
- Notification sent
- Jun 18, 2026
- Affected individuals
- 14
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified the Office of the New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.