HackingStolen CredentialsTargetedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Blue & Co., LLC
bd_e7fa2442cc498e19 · schema v1 · pii pii-v1
Full breach record for Blue & Co., LLC →Blue & Co., LLC notified the NH Attorney General of unauthorized access to a server on November 7, 2024, discovered December 9, 2024. Data copied included names and SSNs affecting 3 NH residents. Blue isolated the server, engaged forensic specialists, notified law enforcement, and provided one year of Kroll credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_ddd75af88e9d2d56Montana State AGfiled 2025-09-22Candidate
- bd_45cafe607b45073bIndiana State AGfiled 2025-09-25(3d gap)Verified
- bd_67d8eaab5e957626Vermont State AGfiled 2025-09-09(13d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/blue-20250922.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2025
- Raw hash
- 00a7f34c2086f0b4405b8642221a330d3e44277cc357c3dc66cd0306843a8502
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Blue & Co., LLCnorm: blue
Incident
- Discovered
- Dec 9, 2024
- Materiality determined
- —
- Notification sent
- Sep 22, 2025
- Affected individuals
- 3
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 41 weeks(287 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.