HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
COMMUNITY CONNECTIONS REAL ESTATE FOUNDATION
bd_e4be22cbcdc30146 · schema v1 · pii pii-v1
Full breach record for COMMUNITY CONNECTIONS REAL ESTATE FOUNDATION →Community Connections, a behavioral health provider, notified the NH Attorney General of a cybersecurity incident discovered on October 21, 2024. Suspicious activity led to forensic investigation revealing unauthorized access to sensitive data including SSNs, medical info, and financial data. One NH resident was affected. Notifications were mailed August 28, 2025, offering 18 months of credit monitoring. Response included engaging forensic firms, disconnecting network access, and changing passwords.
Leak gap clock✗ Leak >180d44 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
A leak claim by inc_ransom about this victim predates this filing by 310 days.View originating leak claim
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/community-connections-20250827.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 27, 2025
- Raw hash
- 80b001323af675ad184c4d6ebdb8db8527d9debe7b85152def197521f4210457
Reporting entity
- Name
- Wilson, Elser, Moskowitz, Edelman & Dicker LLPnorm: wilson elser moskowitz edelman dicker
Victim entity
- Name
- COMMUNITY CONNECTIONS REAL ESTATE FOUNDATIONnorm: community connections real estate
Incident
- Discovered
- Oct 21, 2024
- Materiality determined
- —
- Notification sent
- Aug 28, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 44 weeks(310 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.