BAKER & HOSTETLER LLP
ent_019e10ea253dbf8095b1e454ce07131b
Disclosures
25+
State AG · 6 jurisdictions
Multi-filing incidents
23
incidents joining 2+ filings here
Max affected reported
48,861
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BAKER & HOSTETLER LLP
- Normalized
- baker hostetler— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300TB6RJ6R52PGB17
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (newest 25)newest first
- New Hampshire State AGas reporting2026-09-10
Petco Animal Supplies Stores, Inc. notified the NH Attorney General of unauthorized access to a single employee's Microsoft 365 account. The incident exposed the name and driver's license number of one New Hampshire resident. Petco contained the activity, engaged third-party cybersecurity professionals, and mailed notification letters on September 10, 2026. Two years of credit monitoring via Epiq were offered.
- Iowa State AGas reporting2026-06-01
Strategic Education Inc. notified the Iowa AG of unauthorized access to its network between Feb 23-25, 2026. An actor accessed servers and exfiltrated files containing names, SSNs, driver's licenses, and passport numbers for ~7,157 Iowa residents. Notification letters were mailed starting May 29, 2026, offering Kroll identity monitoring.
- Maryland State AGas reporting2026-04-23
Erb & Young Insurance, Inc. notified the Maryland Attorney General of a security incident involving unauthorized access to employee email accounts between January 7 and January 9, 2025. The breach exposed the names and driver's license numbers of two Maryland residents. Notifications were sent on March 30, 2025, offering one year of credit monitoring and identity theft restoration services.
- New Hampshire State AGas reporting2026-04-08
Luxottica of America, Inc. notified the New Hampshire Attorney General of a data incident affecting one NH resident. An unauthorized individual accessed employee ADP payroll accounts between Feb 6-12, 2026, altering direct deposit info. Luxottica reset passwords, blocked access, reported to law enforcement, and offered 2 years of credit monitoring. Data involved: name and bank account/routing numbers.
- Iowa State AGas reporting2026-03-17
Kaplan North America, LLC notified the Iowa AG of unauthorized access to its computer network between Oct 30 and Nov 18, 2025. The incident exposed names, SSNs, and driver's license numbers of 39,331 Iowa residents. Kaplan secured the network, engaged external IT specialists, alerted law enforcement, and sent notification letters on March 17, 2026, offering one year of credit monitoring.
- Maine State AGas reporting2026-02-04
Corban OneSource, LLC reported an external system breach (hacking) on September 9, 2025, affecting 1,593 individuals, including 2 Maine residents. The incident involved unauthorized access to files containing names and Social Security numbers. Corban secured the network, notified law enforcement, and sent notification letters on February 4, 2026, offering one year of credit monitoring via Epiq.
- Washington State AGas reporting2025-12-23
Smith Fire Systems, Inc. reported unauthorized access to its network between Oct 23 and Nov 9, 2025, discovered on Nov 10, 2025. The incident affected 785 Washington residents, exposing names, SSNs, DOBs, driver's license numbers, and financial account information. Smith Fire notified law enforcement, engaged third-party forensic investigators, and began mailing notifications on Dec 23, 2025, offering one year of credit monitoring.
- Iowa State AGas reporting2025-12-08
CNHI, LLC notified Iowa AG of unauthorized network access between April 27 and May 17, 2025. Files containing names, SSNs, driver's licenses, and financial data of 4,682 Iowa residents were taken. Notification letters mailed December 8, 2025. CNHI secured network, engaged investigators, and offered one year of credit monitoring.
- New Hampshire State AGas reporting2025-11-24
Dartmouth College notified the New Hampshire Attorney General of a security incident involving its Oracle eBusiness Suite (EBS) software. An unauthorized actor exploited a zero-day vulnerability in the software to exfiltrate files containing names, Social Security numbers, and financial account information of 31,742 New Hampshire residents between August 9 and 12, 2025. Dartmouth discovered the incident on October 30, 2025, and began notifying affected individuals on November 24, 2025. Remediation included applying available patches and offering one year of credit monitoring.
- New Hampshire State AGas reporting2025-10-03
The Global Technology Industry Association, Inc. notified the New Hampshire Attorney General of a cybersecurity event involving unauthorized access to a single email account between August 6 and August 11, 2025. The incident exposed the names and Social Security numbers of four New Hampshire residents. GTIA contained the incident, offered one year of credit monitoring, and enhanced security measures.
- New Hampshire State AGas reporting2025-09-18
Pensacola Hospitalist Physicians, LLC notified the NH AG of a third-party business associate breach. Unauthorized access occurred May 22-23, 2025. Patient data (names, DOB, diagnosis, SSN) exposed. Notification mailed Sept 18, 2025. 2 NH residents affected. Credit monitoring offered.
- New Hampshire State AGas reporting2025-09-17
American Pensions Advisors, Inc. notified the NH Attorney General of unauthorized access to a device between April 8-15, 2025. The incident affected 2 NH residents, exposing names, SSNs, driver's license numbers, and financial account numbers. APA engaged a cybersecurity firm, secured the device, and offered one year of credit monitoring through Kroll.
- Rhode Island State AGas reporting2025-09-09
New York Blood Center Enterprises (NYBCe) notified the Rhode Island Attorney General of a cybersecurity incident occurring between January 20 and January 26, 2025. An unauthorized party accessed NYBCe's network and copied files containing names, SSNs, driver's license numbers, and financial account information. NYBCe notified 1,122 Rhode Island residents on September 5, 2025, offering one year of credit monitoring.
- New Hampshire State AGas reporting2025-09-05
New York Blood Center Enterprises notified the NH Attorney General of a cybersecurity incident occurring between Jan 20-26, 2025. An unauthorized party accessed the network and exfiltrated files containing names, SSNs, driver's licenses, and financial account info. 6 NH residents were notified on Sep 5, 2025. The company engaged cybersecurity partners, secured systems, and offered 1 year of credit monitoring.
- Rhode Island State AGas reporting2025-06-24
Sensata Technologies, Inc. notified the Rhode Island Attorney General of a ransomware incident affecting 1,728 RI residents. Unauthorized access occurred between March 28 and April 6, 2025, resulting in encrypted servers and exfiltration of PII including SSNs, financial, and health data. Sensata engaged forensic investigators, notified law enforcement, and provided one year of credit monitoring to affected individuals. Notification letters were mailed on June 5, 2025.
- Washington State AGas reporting2025-03-14
Supplemental notification for Klickitat Valley Health regarding a cyberattack discovered on Feb 23, 2025. Unauthorized access on Feb 18, 2025 exposed PHI, SSNs, and financial data for 11,960 WA residents. Notifications began Mar 14, 2025. Investigation ongoing.
- Maryland State AGas reporting2025-02-07
Heartland Bank notified the Maryland AG of a cybersecurity incident involving unauthorized access to employee email accounts between Oct 31 and Nov 9, 2024. The incident resulted in the exposure of one Maryland resident's name and Social Security number. The bank secured the accounts and mailed notification to the affected individual.
- New Hampshire State AGas reporting2024-11-27
LPGA notified NH AG of unauthorized access to two employee email accounts between Aug 19-22, 2024. One NH resident's info was compromised. Notification sent Nov 22, 2024. Experian credit monitoring offered.
- Washington State AGas reporting2024-08-23
Supplemental notification for Okanogan Behavioral HealthCare regarding a May 2024 ransomware incident affecting 15,774 Washington residents. The breach exposed PHI, SSNs, and IDs. Notifications were mailed starting August 23, 2024, with credit monitoring offered.
- Maine State AGas reporting2024-08-07
Heier Weisbrot & Bernstein, LLC, a professional services firm, experienced an external system breach between June 22-26, 2024. An unauthorized actor accessed tax software, leading to attempted fraudulent tax filings for clients. Seven Maine residents were affected, with data including names, SSNs, driver's license numbers, and financial account numbers exposed. Notifications were sent on August 7, 2024, offering one year of identity protection services.
- Maine State AGas reporting2024-06-05
Tulane University reported a data breach affecting a former third-party vendor. The breach, which occurred between December 14 and December 18, 2023, involved the unauthorized acquisition of data from an archived website. The compromised data included names and financial account or credit/debit card numbers along with their corresponding security codes or PINs. The university began notifying the 10 affected Maine residents on June 5, 2024.
- Maine State AGas reporting2024-05-08
The Dufresne Spencer Group, LLC reported an external system breach (hacking) occurring on May 15, 2023, discovered on January 15, 2024. The incident affected 7 Maine residents. Compromised data included names and driver's license numbers. Written notification was sent on May 8, 2024, and 1 year of credit monitoring via Equifax was offered.
- Maine State AGas reporting2024-04-09
Bristol Bay Construction Holdings experienced an external system breach on November 6, 2023, which was discovered on January 9, 2024. The breach compromised the names and Social Security numbers of 27 Maine residents. In response, the company provided affected individuals with written notification on April 9, 2024, and offered one year of credit monitoring and identity protection services through Lifelock.
- Maine State AGas reporting2024-04-01
Tri Delta, a non-profit organization, reported a data breach affecting 448 individuals. The breach, which occurred and was discovered on March 4, 2024, resulted from a phishing attack. The compromised information included names and Social Security numbers. Affected individuals were notified on April 1, 2024, and offered two years of identity theft protection services through Identity Defense.
- Washington State AGas reporting2023-10-30
Postmeds, Inc. filed a supplemental notification with the Washington AG regarding a cybersecurity incident. A bad actor gained unauthorized access to pharmacy management files between August 30 and September 1, 2023. Postmeds discovered the breach on August 31, 2023. The incident affected 48,861 Washington residents, exposing names, prescription information, and Social Security numbers. Postmeds engaged forensic professionals, secured the environment, and provided credit monitoring services to affected individuals.