HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
Sterling Valley Systems, Inc
bd_117fb177a3acd087 · schema v1 · pii pii-v1
Full breach record for Sterling Valley Systems, Inc →Sterling Valley Systems, Inc. d/b/a Inntopia reported a data breach to the New Hampshire Attorney General on April 18, 2022. Unauthorized access occurred on or around October 9, 2021, and was detected on February 18, 2022. The incident involved the exfiltration of customer PII, including names and government IDs. Inntopia engaged forensic investigators and law enforcement, and provided credit monitoring to affected individuals. The investigation was ongoing at the time of filing.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_82c2b3c04defa461Maine State AGfiled 2022-04-21(3d gap)Verified by operator
- bd_3f3a1da6ae2e8899New Hampshire State AGfiled 2022-04-15(3d gap)Verified
- bd_3329fd7ee3c19b98New Hampshire State AGfiled 2022-04-25(7d gap)Verified
- bd_b45eab07f9b5a950Montana State AGfiled 2022-04-05(13d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 39d gap
- bd_f47f9bc3b239437dNew Hampshire State AGfiled 2022-05-27(39d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sterling-valley-dba-inntopia-20220418.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 18, 2022
- Raw hash
- 0f777872fa6c1c9347b0c5f5f26c1cc0bebd7589524b142aa63683605674057d
Reporting entity
- Name
- Sterling Valley Systems, Incnorm: sterling valley
Victim entity
- Name
- Sterling Valley Systems, Incnorm: sterling valley
Incident
- Discovered
- Feb 18, 2022
- Materiality determined
- —
- Notification sent
- Apr 5, 2022
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed New Hampshire Attorney General breach notification
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.