MalwareRansomwareData EncryptedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
International Shoppes, LLC and Diplomatic Duty Free Shops of New York, Inc.
bd_20576ff1525b9ee0 · schema v1 · pii pii-v1
Full breach record for International Shoppes, LLC and Diplomatic Duty Free Shops of New York, Inc. →International Shoppes, LLC and Diplomatic Duty Free Shops of New York, Inc. reported a ransomware attack discovered on December 1, 2023, with initial access occurring around November 16, 2023. The incident affected personal information of employees, customers, vendors, and visitors, including 2 New Hampshire residents. No actual misuse was confirmed. The company engaged forensic investigators, notified law enforcement (FBI, CISA), and implemented security controls including MFA and VPN restrictions. Affected individuals were offered 24 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/international-shoppes-diplomatic-duty-free-shops-new-york-20240208.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 8, 2024
- Raw hash
- 5eb86894e0bcb38c0246736e2964071fb4b40ae11a5938a0e15d0fa9b14a33ee
Reporting entity
- Name
- International Shoppes, LLC and Diplomatic Duty Free Shops of New York, Inc.norm: international shoppes llc and diplomatic duty free shops of new york
Victim entity
- Name
- International Shoppes, LLC and Diplomatic Duty Free Shops of New York, Inc.norm: international shoppes llc and diplomatic duty free shops of new york
Incident
- Discovered
- Dec 1, 2023
- Materiality determined
- —
- Notification sent
- Feb 8, 2024
- Affected individuals
- 2
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBINotified the U.S. Cybersecurity and Infrastructure Security Agency (CISA)Notified the U.S. Customs and Border Protection
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(69 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.