Social EngineeringPhishingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Statewide Aquastore, Inc.
bd_e273826bed9d4f18 · schema v1 · pii pii-v1
Full breach record for Statewide Aquastore, Inc. →Statewide Aquastore, Inc. notified New Hampshire residents of a data breach involving third-party provider Arete Advisors, LLC. An unauthorized individual sent an email containing personal information (name, SSN) of approximately 35 individuals. Statewide discovered the incident on August 12, 2024, and filed notice with the NH AG on September 5, 2024. Credit monitoring via Experian is offered.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed35 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/statewide-aquastore-20240905.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2024
- Raw hash
- 68626f7d65ae5fdf65b6ffdc9114e1fbc6a1e77a02cfd1219d36b5a6e2bb3b98
Reporting entity
- Name
- Statewide Aquastore, Inc.norm: statewide aquastore
- Domain
- statewideaquastore.com
Victim entity
- Name
- Statewide Aquastore, Inc.norm: statewide aquastore
- Domain
- statewideaquastore.com
Incident
- Discovered
- Aug 12, 2024
- Materiality determined
- —
- Notification sent
- Sep 5, 2024
- Affected individuals
- 35
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- External
- Regulator citations
- providing written notice of this incident to relevant state regulators
- Third party
- via Arete Advisors, LLC
- Initial access
- phishing_link
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.