HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
American Addiction Centers, Inc.
bd_f2aef419fe563786 · schema v1 · pii pii-v1
Full breach record for American Addiction Centers, Inc. →American Addiction Centers, Inc. (AAC) notified the New Hampshire Attorney General of a cybersecurity incident affecting approximately 3,422 NH residents. Unauthorized access occurred between Sept 23-26, 2024. AAC engaged third-party experts, contained the incident, and notified law enforcement. Personal information including names and SSNs was accessed. AAC offered credit monitoring and implemented additional security protocols.
Leak gap clock⏱ Leak >30d13 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
A leak claim by rhysida about this victim predates this filing by 88 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_824b9fda62106035Leak Siterhysidafiled 2024-11-16(37d gap)Verified
- bd_368ecb5209c5fca1Leak Siterhysidafiled 2024-09-26(88d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_9c951622ce1ae877Maine State AGfiled 2024-12-23Verified
- bd_10443d8cd56b6545HHS OCRfiled 2024-11-25(28d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/american-addiction-centers-20241223.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2024
- Raw hash
- 793c7f94985df30610e9d699779c0ed6245b5319c7f7370aba441d2880c32954
Reporting entity
- Name
- American Addiction Centers, Inc.norm: american addiction centers
- Domain
- americanaddictioncenters.org
Victim entity
- Name
- American Addiction Centers, Inc.norm: american addiction centers
- Domain
- americanaddictioncenters.org
Incident
- Discovered
- Sep 26, 2024
- Materiality determined
- —
- Notification sent
- Dec 23, 2024
- Affected individuals
- 3,422
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Secretary of Health and Human Services, Office for Civil Rights
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 weeks(88 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.