HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Bare Root Trees: Seedlings & Saplings l Chief River Nursery
bd_f4ec6db0c22c1d65 · schema v1 · pii pii-v1
Full breach record for Bare Root Trees: Seedlings & Saplings l Chief River Nursery →Chief River Nursery notified the New Hampshire Attorney General on June 1, 2026, of a data event affecting 55 NH residents. Between Feb 12 and March 17, 2026, payment card data and names were copied from the company's checkout page without authorization. The company investigated, notified residents and credit bureaus, and is reviewing security policies.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3427bc493cbeb57fMaine State AGfiled 2026-06-01Verified
- bd_76be031a5278e25aVermont State AGfiled 2026-06-01Verified
- bd_cd4d8dc6b4ef5866Indiana State AGfiled 2026-06-01Verified
- bd_d71135acde73d686Massachusetts State AGfiled 2026-06-01Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/chief-river-nursery-20260601.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- 212c7a08aee575cb0e7229cb715e4cacf5eee11d4e4f3f8c7d8a3fb5ef70a1b0
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Bare Root Trees: Seedlings & Saplings l Chief River Nurserynorm: bare root trees seedlings saplings l chief river nursery
- Domain
- chiefrivernursery.com
Incident
- Discovered
- Mar 17, 2026
- Materiality determined
- —
- Notification sent
- Jun 1, 2026
- Affected individuals
- 55
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.