HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Carter Community Building Association
bd_f4887f5d9611b943 · schema v1 · pii pii-v1
Full breach record for Carter Community Building Association →Carter Community Building Association (CCBA) notified the New Hampshire Attorney General's Office of a cybersecurity incident affecting 288 NH residents. An unauthorized actor accessed CCBA's payroll system and an employee email account between July 22 and July 26, 2025. CCBA discovered the breach on October 17, 2025, following a forensic investigation. Affected data included names, SSNs, driver's license numbers, passport numbers, and financial account information. CCBA provided written notifications and complimentary credit monitoring services starting November 17, 2025.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_7493a1492f88e603Vermont State AGfiled 2025-11-17(4d gap)Candidate
- bd_d25813368908472dIndiana State AGfiled 2025-11-17(4d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/carter-community-building-association-20251121.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2025
- Raw hash
- 8d5bfbfd14394639142df3aaf5b8eb245e027693791be4995fe448f71f1a0240
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- Carter Community Building Associationnorm: carter community building
Incident
- Discovered
- Oct 17, 2025
- Materiality determined
- —
- Notification sent
- Nov 17, 2025
- Affected individuals
- 288
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.