HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Restaurant Management Company of Wichita, Inc.
bd_f67f346db1f6ee32 · schema v1 · pii pii-v1
Full breach record for Restaurant Management Company of Wichita, Inc. →Restaurant Management Company of Wichita, Inc. notified the New Hampshire Attorney General of a security incident affecting 20 NH residents. Unauthorized access occurred between October 4 and October 13, 2025. The breach exposed names, addresses, DOBs, SSNs, driver's license numbers, and financial account details. RMC engaged forensic investigators and outside counsel, reset passwords, rebuilt servers, and provided one year of Experian credit monitoring to affected individuals. Notices were mailed starting April 20, 2026.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_4197eb822c7b9281Indiana State AGfiled 2026-04-20Candidate
- bd_5035bd5b08d071f0Indiana State AGfiled 2026-04-20Candidate
- bd_8e2220c9a2d14a40Maine State AGfiled 2026-04-20Verified by operator
- bd_b63d164a416d9d16Texas State AGfiled 2026-04-22(2d gap)Verified by operator
Show 2 more filings ↓Show fewer ↑up to 11d gap
- bd_57e52e0fce5fc901Vermont State AGfiled 2026-04-17(3d gap)Verified
- bd_dd5cc7ea04c6bf0eMassachusetts State AGfiled 2026-05-01(11d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/restaurant-management-company-wichita-20260420.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 20, 2026
- Raw hash
- a0bb8bd9c1cea52b2abd9d0fe130fd471540c9fe0365fb42bfbdd1fcf0b9b8e4
Reporting entity
- Name
- Restaurant Management Company of Wichita, Inc.norm: restaurant management company of wichita
Victim entity
- Name
- Restaurant Management Company of Wichita, Inc.norm: restaurant management company of wichita
Incident
- Discovered
- Oct 13, 2025
- Materiality determined
- —
- Notification sent
- Apr 20, 2026
- Affected individuals
- 20
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 weeks(189 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.