HackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPIIMediumContained
Arthur Ashe Institute for Urban Health Inc
bd_ecfdcd155a189852 · schema v1 · pii pii-v1
Full breach record for Arthur Ashe Institute for Urban Health Inc →Arthur Ashe Institute for Urban Health Inc. notified the New Hampshire Attorney General of a cyberattack occurring between April 4, 2025, and May 18, 2025. The incident involved unauthorized access to PII of 1 New Hampshire resident, including names, SSNs, driver's licenses, financial account info, and medical data. The organization detected the breach on September 22, 2025, implemented MFA, updated passwords, and provided 12 months of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_c1f899c2458ec7b8Indiana State AGfiled 2026-01-22(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/arthur-ashe-institute-urban-health-20260123.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 23, 2026
- Raw hash
- f948d2a557fb9ff2ebfa49c362b329ae684903588201d9e1424f135ac5601be7
Reporting entity
- Name
- Jackson Lewisnorm: jackson lewis
- Domain
- jacksonlewis.com
Victim entity
- Name
- Arthur Ashe Institute for Urban Health Incnorm: arthur ashe institute for urban health
Incident
- Discovered
- Sep 22, 2025
- Materiality determined
- —
- Notification sent
- Jan 23, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection and Antitrust Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 weeks(123 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.