HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Mercy Center, Inc.
bd_f0e4c4ab2aacf49e · schema v1 · pii pii-v1
Full breach record for Mercy Center, Inc. →Mercy Center, Inc. notified the New Hampshire Attorney General of a cybersecurity incident discovered on June 18, 2025. Suspicious network activity led to system disconnection and forensic investigation. A limited number of documents containing names, SSNs, driver's licenses, financial, and medical data were accessed. One NH resident was notified on December 18, 2025. The organization offered 12 months of credit monitoring and implemented enhanced security controls.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mercy-center-20251226.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 26, 2025
- Raw hash
- 7bfea50f7c904f23ebad88fc1bfe2d0c326f0200a3f3c99944324e84f5c75a10
Reporting entity
- Name
- Mercy Center, Inc.norm: mercy center
Victim entity
- Name
- Mercy Center, Inc.norm: mercy center
Incident
- Discovered
- Jun 18, 2025
- Materiality determined
- —
- Notification sent
- Dec 18, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Office of the Attorney General
Compliance
- Time to disclose
- 27 weeks(191 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.