HackingStolen CredentialsData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
H&N Tax, Inc
bd_f80f9ab6352f9e98 · schema v1 · pii pii-v1
Full breach record for H&N Tax, Inc →H&N Tax, Inc. d/b/a CSA Tax notified consumers of a December 2, 2025 incident involving unauthorized access to a network. The breach potentially exposed names and Social Security numbers. The company engaged forensic specialists, secured the environment, and offered 12 months of credit monitoring. No specific total count was disclosed, though 4 Rhode Island residents were explicitly identified.
Vermont clock✗ VT AG >45 bday11 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3d4f05ec1dffaa1bMaine State AGfiled 2026-02-20Candidate
- bd_efcdb3c974c3d568New Hampshire State AGfiled 2026-02-20Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-02-20-hn-tax-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 20, 2026
- Raw hash
- feecec069c64837bc28865f086623b99aeac5a5ab029ae9806fa06d12a5ee1e2
Reporting entity
- Name
- H&N Tax, Incnorm: h n tax
Victim entity
- Name
- H&N Tax, Incnorm: h n tax
Incident
- Discovered
- Dec 2, 2025
- Materiality determined
- —
- Notification sent
- Feb 20, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(80 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.