HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Newbridge Securities Corporation
bd_ef2137acf08ba54a · schema v1 · pii pii-v1
Full breach record for Newbridge Securities Corporation →Newbridge Securities Corporation notified the New Hampshire Attorney General of a network intrusion occurring between February 24 and March 18, 2021. The company discovered the breach on August 30, 2021, after determining that personal information of 77 NH residents, including names, addresses, SSNs, and account details, may have been accessed. Newbridge engaged a cybersecurity firm, secured its network, and offered one year of complimentary identity monitoring via Kroll/Experian. Remediation included MFA implementation, legacy auth removal, and enhanced logging.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_17038b233b71647eMontana State AGfiled 2021-10-14Candidate
- bd_8b3162b529c149d3Maine State AGfiled 2021-10-14Verified by operator
- bd_d2ca3d9293e68dfeCalifornia State AGfiled 2021-10-14Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/newbridge-securities-20211014.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 14, 2021
- Raw hash
- 3c6ace8ca40d7fd1eddf2e06a9691fdd2bbff0166dc8b58c709e54a05ba62a0b
Reporting entity
- Name
- John P. Hutchinsnorm: john p hutchins
Victim entity
- Name
- Newbridge Securities Corporationnorm: newbridge securities
Incident
- Discovered
- Aug 30, 2021
- Materiality determined
- —
- Notification sent
- Oct 14, 2021
- Affected individuals
- 77
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.