HackingStolen CredentialsData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALHEALTH_BASICMediumContained
Tuggle Duggins
bd_e6e95a619ddf2a73 · schema v1 · pii pii-v1
Full breach record for Tuggle Duggins →Tuggle Duggins P.A., a law firm, reported unauthorized access to its computer systems on October 1, 2024. The incident resulted in the copying of files containing names, Social Security numbers, employment information, and health/financial data. Approximately one New Hampshire resident was affected. The firm notified federal law enforcement, implemented additional cybersecurity safeguards, and provided one year of complimentary credit monitoring through Experian.
Leak gap clock✗ Leak >180d13 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
A leak claim by black_basta about this victim predates this filing by 387 days.View originating leak claim
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/tuggle-duggins-20251022.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 22, 2025
- Raw hash
- b063ca6e840e4cd4a927ed1b59b26a90c8d0508d0efaaed7de1aeed79a74e457
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Tuggle Dugginsnorm: tuggle duggins
- Domain
- tuggleduggins.com
Incident
- Discovered
- Oct 1, 2024
- Materiality determined
- —
- Notification sent
- Oct 22, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement regarding the event
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 months(386 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.