Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Roger Keith and Sons Insurance Agency
bd_e1cea9af07d1724a · schema v1 · pii pii-v1
Full breach record for Roger Keith and Sons Insurance Agency →Roger Keith & Sons Insurance Agency notified the New Hampshire Attorney General on November 3, 2025, regarding a phishing incident discovered on January 27, 2025. An unauthorized party accessed an employee email account and network via a remote desktop tool. The breach affected 12 New Hampshire residents, exposing names, SSNs, and driver's license numbers. The agency contained the network, engaged forensic investigators, and is offering credit monitoring to affected individuals.
Leak gap clock✗ Leak >180d40 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by silentransomgroup about this victim predates this filing by 211 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a5dda1583c1020cfVermont State AGfiled 2025-10-29(5d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/roger-keith-sons-insurance-agency-20251103.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 3, 2025
- Raw hash
- f573ad7f2ec515231491e7e6aa9bcaf7a81c1cf9f09848c81f8f94c581b195c6
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- Roger Keith and Sons Insurance Agencynorm: roger keith and sons insurance agency
- Domain
- rogerkeith.com
Incident
- Discovered
- Jan 27, 2025
- Materiality determined
- —
- Notification sent
- Oct 29, 2025
- Affected individuals
- 12
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided notification to the Office of the New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- phishing_link
Compliance
- Time to disclose
- 40 weeks(280 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.