HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPIIMediumContained
University of St. Thomas - Houston
bd_fbc9720e76119e2a · schema v1 · pii pii-v1
Full breach record for University of St. Thomas - Houston →University of St. Thomas-Houston notified the New Hampshire Attorney General of a data event affecting 6 NH residents. Unauthorized access occurred between July 25, 2025, and August 12, 2025. Impacted data included names, SSNs, DOBs, financial account info, and health insurance info. USTH engaged third-party specialists, notified law enforcement, and provided 12 months of credit monitoring via Experian.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_c8affa11c4871b0dTexas State AGfiled 2026-05-28(1d gap)Verified by operator
- bd_037d756f27dcba8fIndiana State AGfiled 2026-05-26(1d gap)Verified by operator
- bd_3dbc3d21cb3f1e7fVermont State AGfiled 2026-05-26(1d gap)Verified
- bd_a02c5ca4989a76f7Maine State AGfiled 2026-05-26(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 79d gap
- bd_f485349c6738905aMassachusetts State AGfiled 2026-05-01(26d gap)Verified by operator
- bd_ade2037bf6e50199Texas State AGfiled 2026-03-09(79d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/university-st-thomas-houston-20260527.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 27, 2026
- Raw hash
- ecdc43e07c4158e89dff5ba6ece322c2cd9827d71e768f1c04e286a3c388b61f
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- University of St. Thomas - Houstonnorm: university of st thomas houston
Incident
- Discovered
- Aug 12, 2025
- Materiality determined
- —
- Notification sent
- Mar 26, 2026
- Affected individuals
- 6
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection & Antitrust BureauNotified federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 41 weeks(288 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.