HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Asheville Eye Associates, PLLC
bd_fc537b3102571495 · schema v1 · pii pii-v1
Full breach record for Asheville Eye Associates, PLLC →Asheville Eye Associates, PLLC notified New Hampshire AG of a network security incident detected on Nov 18, 2024. Unauthorized access led to exfiltration of PII including SSNs, names, addresses, and medical/insurance info. ~21 NH residents affected. AEA engaged forensic specialists, notified law enforcement, and provided credit monitoring.
Leak gap clock✗ Leak >180d30 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
A leak claim by dragonforce about this victim predates this filing by 207 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_5d1589dd656b977aMontana State AGfiled 2025-06-13Candidate
- bd_61636977e5587feaIndiana State AGfiled 2025-06-13Verified
- bd_66c3cf170bf79f25Vermont State AGfiled 2025-06-13Verified
- bd_694b2250a9e049d1South Carolina State AGfiled 2025-06-13Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/asheville-eye-associates-20250613.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 13, 2025
- Raw hash
- 21af26fa259fca2768ca57f3d8f31a2f801cba3f0082fef4ef16d6b1c491fc2a
Reporting entity
- Name
- Asheville Eye Associates, PLLCnorm: asheville eye associates
- Domain
- ashevilleeye.com
Victim entity
- Name
- Asheville Eye Associates, PLLCnorm: asheville eye associates
- Domain
- ashevilleeye.com
Incident
- Discovered
- Nov 18, 2024
- Materiality determined
- Apr 14, 2025
- Notification sent
- Jun 13, 2025
- Affected individuals
- 21
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 30 weeks(207 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.