Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
Commonwealth Trust Company
bd_f6b684516e1c3892 · schema v1 · pii pii-v1
Full breach record for Commonwealth Trust Company →Commonwealth Trust Company notified the NH AG of a data event affecting 4 NH residents. An unauthorized actor accessed an employee email account on May 13, 2025, likely via phishing, obtaining emails containing names, SSNs, financial account info, and PHI. CTC secured the account, investigated, and provided 24 months of credit monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/commonwealth-trust-20250922.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2025
- Raw hash
- 1d44ceec9f573b96ef9d4add7e764e93049e1829ff7cfcad36fcb20d219df572
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Commonwealth Trust Companynorm: commonwealth trust
- Domain
- commonwealth-trust.com
Incident
- Discovered
- May 13, 2025
- Materiality determined
- —
- Notification sent
- Sep 19, 2025
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided notice to New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- phishing_link
Compliance
- Time to disclose
- 19 weeks(132 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.