Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
UHY
bd_f3392e9a209583f8 · schema v1 · pii pii-v1
Full breach record for UHY →UHY Advisors Northeast, Inc. notified the New Hampshire Attorney General of a phishing incident affecting approximately 19 NH residents. An unauthorized individual accessed an employee email account on November 6, 2025, compromising names, SSNs, driver's licenses, and financial account info. UHY engaged outside cybersecurity professionals, conducted an investigation concluding April 1, 2026, and offered one year of complimentary credit monitoring to affected residents. Notifications began April 17, 2026.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed19 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/uhy-advisors-northeast-20260427.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 27, 2026
- Raw hash
- 3c4881f045f5cec54cb82c9d811eab8b56473ad0e2c35bbde8604d30a6c7a5a1
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- UHYnorm: uhy
- Domain
- uhy-us.com
Incident
- Discovered
- Nov 6, 2025
- Materiality determined
- —
- Notification sent
- Apr 17, 2026
- Affected individuals
- 19
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 25 weeks(172 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.