Inotiv, Inc.
bd_ee3cf19cee079632 · schema v1 · pii pii-v1
Full breach record for Inotiv, Inc. →Inotiv, Inc. submitted a supplemental notice to the New Hampshire Attorney General regarding a cybersecurity incident occurring between August 5-8, 2025. The company discovered on November 21, 2025 that a threat actor may have acquired personal information, including names, SSNs, tax IDs, DOBs, and health insurance info. A total of 14 New Hampshire residents were potentially affected. Inotiv notified 11 residents on December 2, 2025, and subsequently identified 3 additional affected residents and 1 resident with additional data types, notifying them on December 23, 2025. The company offered 24 months of credit monitoring via Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 5, 2025
Begins
Nov 21, 2025
Discovered
Dec 23, 2025
Filed
vs. sector median
14 wks faster
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Nebraska State AGbd_9fdb1f68fc6a3e022025-12-23Verified by operator
- Maine State AGbd_d8edef04448918b22025-12-23Verified
- California State AGbd_eff7143c236edf7c2025-12-23Verified
- Vermont State AGbd_c1146c807292b96b2025-12-22 · +1dVerified
Show 6 more filings ↓Show fewer ↑up to 21d gap
- Texas State AGbd_8e132b89047d54ee2025-12-29 · +6dCandidate
- Massachusetts State AGbd_a3d617a135433fef2025-12-03 · +20dVerified
- Nebraska State AGbd_1787a30044a975922025-12-02 · +21dVerified by operator
- New Hampshire State AGbd_44e1e024dc1bcc1c2025-12-02 · +21dVerified
- California State AGbd_62110b9d0e035dd62025-12-02 · +21dVerified
- Maine State AGbd_6cafa0e37330d9092025-12-02 · +21dVerified
Showing first 10 of 15 linked disclosures.
Filing propagation · 11 filings · 7 states
View merged incident ↗Pattern: first filing Dec 2 (NE), last Dec 29 (TX) — a 27-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 15 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.