Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
State AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedhigh sensitivity
Affected (total reported)
23
Data types
2
Identity (basic) · Government ID
Jurisdictions
2
CA NH
Linked filings
3
all State AG
Sensitive data
identity_government
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Sep 16, 2025
When the intrusion reportedly occurred, per the linked filings
Breach discovered
Sep 16, 2025
Reported by NEW HAMPSHIRE AG filing
42 days
3 State AG filingsOct 28, 2025 – Nov 14, 2025ExpandCollapse
NHCA
⛰️New Hampshire State AGlinked via multistate filing link · 100%
Form Energy, Inc. notified the New Hampshire Attorney General of a ransomware attack discovered on September 16, 2025. The incident impacted 23 New Hampshire residents (employees and beneficiaries), exposing PII including names, addresses, SSNs, and bank account numbers. Form Energy took systems offline, engaged forensic experts, and provided credit monitoring services.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Form Energy, Inc. reported a data security breach to the California Attorney General. The incident occurred on September 16, 2025. The notice indicates that personally identifiable information, including credit report information and financial account data, was potentially compromised. Affected individuals are offered 24 months of complimentary credit monitoring and identity theft prevention services through Experian. The specific cause of the breach and the number of affected individuals are not disclosed in the provided documents.
Form Energy, Inc. submitted a data security breach notification to the California Office of the Attorney General on September 16, 2025. The incident involved unauthorized access to customer data, resulting in the exposure of personally identifiable information and government identifiers. The company provided affected individuals with complimentary credit monitoring, identity theft prevention services, and identity restoration support through Experian for a 24-month period.