MalwareRansomwareData EncryptedDelayed DiscoveryPIIIDENTITY_BASICLowActive
PMA Consultants
bd_fee1b469d6f3bacd · schema v1 · pii pii-v1
Full breach record for PMA Consultants →PMA Consultants, a professional services firm, notified the New Hampshire Attorney General on January 30, 2025, of a ransomware attack discovered on May 7, 2024. The incident affected 4 New Hampshire residents. PMA engaged third-party forensic specialists, reported to federal law enforcement, and sent notices to affected individuals offering credit monitoring. The scope of data exposure was determined through a comprehensive review completed in December 2024.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_e55973011bb404beMaine State AGfiled 2025-01-30Candidate
- bd_7b8da585f4ff4455Maine State AGfiled 2025-03-17(46d gap)Verified
- bd_7d2860b96ee0522aNew Hampshire State AGfiled 2025-03-17(46d gap)Verified
- bd_93723ad4fd281834Indiana State AGfiled 2025-03-17(46d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 46d gap
- bd_fd0865727c08d584Maryland State AGfiled 2025-03-17(46d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pma-consultants-20250130.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2025
- Raw hash
- 063e5068b2abe1fa33b0d7ac09d091c2aa6033d1164887d83b46ccb2245305dc
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- PMA Consultantsnorm: pma consultants
Incident
- Discovered
- May 7, 2024
- Materiality determined
- —
- Notification sent
- Jan 29, 2025
- Affected individuals
- 4
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this incident to federal law enforcement
Compliance
- Time to disclose
- 38 weeks(268 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.