HackingVulnerability ExploitCapture Stored DataZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICPIILowContained
BISSELL, Inc
bd_0cba799bed55bffa · schema v1 · pii pii-v1
Full breach record for BISSELL, Inc →Bissell, Inc. notified the New Hampshire Attorney General of a supply-chain breach involving its vendor Fortra's GoAnywhere file transfer platform. Unauthorized actors exploited a zero-day vulnerability between Jan 28-31, 2023, to exfiltrate files. Bissell learned of the incident in Feb 2023 and confirmed on March 27, 2023, that PII (names, addresses) of 5 NH residents was compromised. Bissell engaged law enforcement and offered 1 year of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_45820182c3db882fVermont State AGfiled 2023-04-20Verified
- bd_4ee3cba7b773cc10Maine State AGfiled 2023-04-20Candidate
- bd_5c73077d258932bcMontana State AGfiled 2023-04-20Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/bissell-20230420.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 20, 2023
- Raw hash
- 0d66d50dd5e0fa5a84dfe34240f6f4c9e8efc3a2d71d7e6a9c1e121c0ea60ff6
Reporting entity
- Name
- BISSELL, Incnorm: bissell
Victim entity
- Name
- BISSELL, Incnorm: bissell
Incident
- Discovered
- Feb 1, 2023
- Materiality determined
- Mar 27, 2023
- Notification sent
- Apr 20, 2023
- Affected individuals
- 5
- Data types
- IDENTITY_BASICPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Third party
- via Fortra
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.