DisclosureLens
AccidentalOtherMisdeliverySupply Chain (3P Vendor)Employee Data InvolvedIdentity (basic)Government IDEmploymentMediumResolved

Clysar

bd_0b2a6b7597c0d683 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 23, 2017

Filed

May 26, 2017

To disclose

18 weeks

Affected

1state residents only

Confidence

67%
Full breach record for Clysar

Clysar, LLC notified the NH Attorney General that employee W-2 forms containing names, addresses, and social security numbers were potentially compromised due to a misdelivery by a third-party vendor (Paychex) via the Postal Service. One New Hampshire resident was affected. The incident was discovered on January 23, 2017, and employees were notified on January 27, 2017. Credit monitoring was provided.

Incident timeline

discovery → filing · 18 weeks / 123 days

Jan 23, 2017

Discovered

May 26, 2017

Filed

vs. sector median

+10 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.