HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTAUTHENTICATIONMediumContained
Davies, McFarland & Carroll LLC
bd_fe3d861d5d324329 · schema v1 · pii pii-v1
Full breach record for Davies, McFarland & Carroll LLC →Davies, McFarland & Carroll LLC (DMC), a law firm, notified the New Hampshire Attorney General of a cybersecurity incident affecting approximately 6 NH residents. Unauthorized access to DMC's internal network occurred between May 19-22, 2025. Personal information potentially accessed included names, DOBs, driver's licenses, financial account numbers, and SSNs. DMC engaged cybersecurity experts, contained the breach, and provided 12 months of credit monitoring to affected individuals. Notification letters were sent on November 24, 2025.
Leak gap clock⏱ Leak >90d28 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by lynx about this victim predates this filing by 179 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_cb9011b811c83da7Leak Sitelynxfiled 2025-06-04(179d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_30ad7f17f1f26299HHS OCRfiled 2025-11-24(7d gap)Verified
- bd_730c57b1011211eaMaine State AGfiled 2025-11-24(7d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/davies-mcfarland-carroll-20251201.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 1, 2025
- Raw hash
- 754c46fde61a551257b790511c54537660934d82187dbdfb75fa3a168ce8e565
Reporting entity
- Name
- McDonaldnorm: mcdonald
- Domain
- mcdonalds-menus.us
Victim entity
- Name
- Davies, McFarland & Carroll LLCnorm: davies mcfarland carroll
Incident
- Discovered
- May 22, 2025
- Materiality determined
- —
- Notification sent
- Nov 24, 2025
- Affected individuals
- 6
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed incident notification with New Hampshire Office of the Attorney General, Consumer Protection Bureau
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 weeks(193 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.