Pierson Ferdinand LLP
ent_9ff0463f4ef897ca043260d9
Disclosures
25+
State AG · 3 jurisdictions
Multi-filing incidents
17
incidents joining 2+ filings here
Max affected reported
56,954
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Pierson Ferdinand LLP
- Normalized
- pierson ferdinand— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- pierferd.com
Disclosure history (newest 25)newest first
- New Hampshire State AGas reporting2026-07-20
Mercadien P.C. CPAs notified the NH AG of a supplemental data incident. An unauthorized actor accessed and acquired files between Sept 17 and Oct 9, 2025. Discovery occurred Nov 7, 2025. 8 NH residents were affected. Data included names and banking/transaction info. Systems were secured and investigation completed. Credit monitoring offered.
- New Hampshire State AGas reporting2026-07-20
M Advisory Group experienced a data security incident on October 20, 2025, involving unauthorized third-party compromise of its email environment. The incident potentially affected one New Hampshire resident, exposing their name and Social Security Number. The company secured the environment, engaged forensic experts, and notified the affected individual on July 2, 2026, offering 12 months of credit monitoring.
- New Hampshire State AGas reporting2026-06-01
Morning Star Tours experienced a data security incident between April 22-23, 2026, involving the compromise of servers maintained by a third-party MSP. The incident potentially affected the names, dates of birth, and passport information of 17 New Hampshire residents. The company reported the incident to law enforcement, engaged cybersecurity counsel, and implemented remediation measures including organization-wide MFA and password resets. Notification letters were mailed on June 1, 2026.
- New Hampshire State AGas reporting2026-05-26
Supplemental notice from Georgia Heritage Federal Credit Union correcting the date of discovery for a previously reported data security incident. The correct discovery date is January 25, 2025, correcting a prior error of February 10, 2025.
- New Hampshire State AGas reporting2026-05-26
LEARN Regional Educational Service Center reported a ransomware incident to the New Hampshire Attorney General on May 26, 2026. The incident occurred on or around April 21, 2025, and was discovered on April 23, 2025. One New Hampshire resident was affected, with their name and Social Security Number compromised. LEARN engaged forensic experts, notified law enforcement, and provided the affected individual with 12 months of credit monitoring and identity theft recovery services through Epiq.
- New Hampshire State AGas reporting2026-04-27
Georgia Heritage Federal Credit Union notified the New Hampshire Attorney General of a ransomware incident occurring on or about January 25, 2025, and discovered on or about February 10, 2025. The breach affected 12 New Hampshire residents, exposing names, financial account numbers, dates of birth, and Social Security numbers. GA Heritage engaged forensic investigators, secured its network, reset credentials, and mailed notification letters on January 15, 2026, offering credit monitoring and identity theft recovery services.
- New Hampshire State AGas reporting2026-04-17
Georgia Heritage Federal Credit Union notified the NH Attorney General of a ransomware incident occurring on Jan 25, 2025, discovered Feb 10, 2025. 12 NH residents affected; data included names, SSNs, DOBs, and financial account numbers. Notifications mailed Jan 15, 2026, offering credit monitoring.
- New Hampshire State AGas reporting2026-04-13
New Hampshire AG submission dated March 26, 2026, regarding Eastern Ice. On January 13, 2026, an unauthorized third party compromised Eastern Ice's network. The incident potentially impacted personal information including name, SSN, DOB, and driver's license numbers for approximately 73 individuals (including 1 NH resident). Eastern Ice engaged third-party experts, secured the network, and mailed notification letters on March 23, 2026, offering 12 months of credit monitoring.
- Maine State AGas reporting2026-04-09
SDI Management LLC reported an external system breach (hacking) occurring on Feb 22, 2026, discovered on Feb 25, 2026. 580 individuals affected, including 2 Maine residents. Compromised data included names, DOBs, SSNs, and driver's licenses. Notification sent April 9, 2026, with credit monitoring offered.
- New Hampshire State AGas reporting2026-04-02
Five States Energy Company, L.L.C. notified the New Hampshire Attorney General on April 2, 2026, of a network compromise detected on February 12, 2026. The incident affected 10 New Hampshire residents, exposing names, SSNs, DOBs, contact info, and bank account numbers. The company engaged forensic experts, notified law enforcement, and provided 24 months of credit monitoring via CyberScout. The incident is contained.
- Maine State AGas reporting2026-03-17
Greenhouse Apartments experienced an external system breach (hacking) on September 20-21, 2025, discovered on February 5, 2026. The incident affected 3,473 individuals, including 6 Maine residents. Personal information including names and other personal identifiers was potentially compromised. The company engaged a cybersecurity firm, notified the Maine AG, and provided credit monitoring services to affected individuals.
- Maine State AGas reporting2026-02-24
Data Systems Analysts, Inc. reported an external system breach (hacking) on September 11, 2025, affecting 3,239 individuals nationwide, including 3 Maine residents. The incident involved unauthorized access to personal information such as names and government identifiers. The company notified affected individuals on February 6, 2026, and provided 12 months of credit monitoring services through Experian.
- Maine State AGas reporting2026-02-20
Greater Pittsburgh Orthopedic Associates Inc. reported a data breach affecting 56,954 individuals, including 3 Maine residents. Unauthorized access occurred on August 9, 2025, and was discovered on August 10, 2025. Compromised data included names, addresses, SSNs, and provider names. The organization engaged forensic experts, notified law enforcement, and offered credit monitoring via Cyberscout.
- New Hampshire State AGas reporting2026-01-05
Mercadien PC, a CPA firm, notified the New Hampshire Department of Justice of a data security incident discovered on November 7, 2025. Unauthorized access occurred between September 17 and October 9, 2025. The investigation is ongoing, and the number of affected individuals is currently unknown. Law enforcement was notified, and forensic experts are engaged. Remediation includes password resets and deploying SentinelOne.
- Maine State AGas reporting2025-11-07
Opus Card Systems, Inc. reported an external system breach (hacking) on July 21, 2025, affecting 330 individuals, including 2 Maine residents. Personal identifiers and government IDs were compromised. Notifications were sent on November 3, 2025, offering credit monitoring via CyberScout.
- New Hampshire State AGas reporting2025-11-07
Opus Card Systems, Inc. notified the New Hampshire Attorney General of a data security incident involving a third-party processor. On July 21, 2025, Opus was alerted to potential compromise of personal data. A forensic investigation confirmed unauthorized access to files containing New Hampshire residents' full names, Social Security numbers, and driver's license or passport information. Two residents were notified on November 3, 2025, and offered 12 months of credit monitoring. No fraud has been reported.
- New Hampshire State AGas reporting2025-10-22
Shiftster LLC, owner of the ESHYFT nursing staffing platform, disclosed a data security incident involving an unauthorized AWS S3 bucket access. The incident, first reported by a 'cyber security researcher' on Jan 6, 2025, resulted in the exposure of personal and health information for at least one New Hampshire resident. Affected data included names, DOBs, addresses, VINs, driver's license numbers, and health info. Shiftster secured the bucket and offered credit monitoring.
- New Hampshire State AGas reporting2025-09-24
Nusbaum Insurance Agency notified the New Hampshire AG of a data security incident in August 2024 where an unauthorized third party accessed its email environment. The incident potentially exposed customer names, SSNs, driver's license numbers, dates of birth, and health information. Three New Hampshire residents were notified on September 11, 2025. Nusbaum engaged forensic experts and offered credit monitoring.
- New Hampshire State AGas reporting2025-09-02
PAC Strapping Products, Inc. experienced a ransomware incident between March 26 and April 2, 2025, affecting 3 New Hampshire residents. The incident involved the exposure of names, credit/debit card numbers, and CVV/expiration dates. The company notified the NH Attorney General on August 28, 2025, and mailed consumer notifications on August 4, 2025. Forensic investigation was conducted, and credit monitoring services were offered.
- Nebraska State AGas reporting2025-08-08
Shiftster LLC (dba ESHYFT) disclosed a data security incident involving an unauthorized AWS S3 bucket access starting Jan 6, 2025. Discovered March 12, 2025, the breach affected up to 3,673 individuals, including names, DOB, addresses, VINs, driver's licenses, and health info. 94 individuals had SSN/DL impacted. Notifications mailed Aug 8, 2025. Shiftster secured the bucket and offered credit monitoring.
- Maine State AGas reporting2025-08-05
PAC Strapping Products, Inc. reported a ransomware incident occurring on March 26, 2025, discovered on April 2, 2025. The breach affected 647 individuals, including 2 Maine residents. Compromised data included names and credit/debit card numbers with CVV. The company engaged forensic investigators, reset passwords, notified law enforcement, and offered 12 months of credit monitoring.
- New Hampshire State AGas reporting2025-08-05
PAC Strapping Products, Inc. experienced a ransomware incident between March 26 and April 2, 2025, affecting three New Hampshire residents. The compromised data included names, credit/debit card numbers, and CVV/expiration dates. The company engaged forensic specialists, notified law enforcement, and implemented additional security measures. Affected individuals were notified via mail on August 4, 2025, and offered 12 months of credit monitoring and identity theft recovery services.
- Maine State AGas reporting2025-06-16
Shrader & Associates, LLP reported a ransomware incident on April 8, 2025, discovered on April 9, 2025. The breach affected 525 individuals, including 3 deceased Maine residents. Compromised data included names, SSNs, and medical records. The firm engaged forensic investigators, reported to the FBI, and provided 24 months of dark web monitoring via TransUnion/Cyberscout to affected families.
- New Hampshire State AGas reporting2025-05-12
Andy Frain Services Inc. reported a network compromise detected on October 23, 2024. An unauthorized third party accessed personal information of 34 New Hampshire residents, including HR files containing PII and government IDs. AFS engaged forensic experts, secured the network, and notified the NH Attorney General. Notifications were mailed on May 5, 2025, offering credit monitoring.
- Maine State AGas reporting2025-02-19
Ascension Capital Partners, a financial services firm, disclosed a data breach where an unauthorized third party accessed a Microsoft 365 email account on May 15, 2024. The incident exposed names, dates of birth, and Social Security numbers of 136 individuals. Ascension secured the account, engaged forensic experts, and offered 12 months of identity monitoring via Kroll.