HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
John P. Meehan Agency, Inc.
bd_e4d5e36aabb7e9c6 · schema v1 · pii pii-v1
Full breach record for John P. Meehan Agency, Inc. →John P. Meehan Agency, Inc. reported a security breach to the New Hampshire Attorney General on November 21, 2025. Unauthorized access to a single employee's Microsoft 365 email account occurred between July 2 and July 8, 2024. The incident potentially exposed the names, Social Security numbers, and driver's license numbers of 6 New Hampshire residents. The agency engaged forensic investigators, offered 12 months of credit monitoring via Kroll, and notified affected individuals on November 19, 2025.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_4fae4fbaa5b90847Maine State AGfiled 2025-11-21Verified
- bd_9d11ac14a058d2deVermont State AGfiled 2025-11-21Candidate
- bd_cfaed4930f9ad271Indiana State AGfiled 2025-11-19(2d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/john-meehan-agency-20251121.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2025
- Raw hash
- 0175b2065f0661571f20839e7c29cf3f96d365b6af9cc10236ee2f09c5e8f48a
Reporting entity
- Name
- Kennedys CMK LLPnorm: kennedys cmk
Victim entity
- Name
- John P. Meehan Agency, Inc.norm: john p meehan agency
Incident
- Discovered
- Jul 8, 2024
- Materiality determined
- —
- Notification sent
- Nov 19, 2025
- Affected individuals
- 6
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified the Pennsylvania Insurance Department (PDI) on September 25, 2024
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 months(501 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.