HackingCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Big Brothers Big Sisters
bd_f793da00c6d19677 · schema v1 · pii pii-v1
Full breach record for Big Brothers Big Sisters →Big Brothers Big Sisters of America (BBBSA) notified the New Hampshire Attorney General of a security incident occurring on or about March 28, 2023. The breach affected approximately 35 New Hampshire residents, exposing personal information including Social Security numbers. BBBSA engaged external cybersecurity professionals, contained the threat, and conducted a manual review. Notices were sent to affected individuals on November 22, 2023, offering credit monitoring and fraud alert guidance.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_00be541af1bd1c26Washington State AGfiled 2023-11-22Verified
- bd_326cb9b1491d0acfDelaware State AGfiled 2023-11-22Verified
- bd_5298e72032a99f4bDelaware State AGfiled 2023-11-22Verified
- bd_966c4007faa4a2f8Vermont State AGfiled 2023-11-22Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- bd_bc1e14d477ece04aMaine State AGfiled 2023-11-22Verified
- bd_d7ba25bbba1c1613California State AGfiled 2023-11-22Verified
- bd_5eb645451e1676d1Montana State AGfiled 2023-11-21(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/big-brothers-big-sisters-america-20231122.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2023
- Raw hash
- 193dd8fb30f76fa1b1d5e4029bec259e54ca3b4f7727b7b36b3aecb54063a4c6
Reporting entity
- Name
- McDonaldnorm: mcdonald
- Domain
- mcdonalds-menus.us
Victim entity
- Name
- Big Brothers Big Sistersnorm: big brothers big sisters
- Domain
- bigs.org
Incident
- Discovered
- Mar 28, 2023
- Materiality determined
- —
- Notification sent
- Nov 22, 2023
- Affected individuals
- 35
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- External
Compliance
- Time to disclose
- 34 weeks(239 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.