HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
CareCentrix
bd_df351fd22bc591a3 · schema v1 · pii pii-v1
Full breach record for CareCentrix →CareCentrix, Inc. notified the New Hampshire Attorney General's office of a cybersecurity incident involving unauthorized access to its systems. The breach affected approximately 10,000 New Hampshire residents, exposing personal information including names, Social Security numbers, and dates of birth. The incident involved the use of stolen credentials to access customer data. CareCentrix engaged forensic investigators and law enforcement, and sent notifications to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed10,000 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/carecentrix-20160321.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 21, 2016
- Raw hash
- 4a7399daabcff041fcb263a2f47db995fd9ae3bcfa0a112845d2b579bafb59bc
Reporting entity
- Name
- CareCentrixnorm: carecentrix
- Domain
- carecentrix.com
Victim entity
- Name
- CareCentrixnorm: carecentrix
- Domain
- carecentrix.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 10,000
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.