HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedPIIFINANCIAL_ACCOUNTLowContained
Zephyr Ventilation
bd_24115f5ddff4f42f · schema v1 · pii pii-v1
Full breach record for Zephyr Ventilation →Zephyr Ventilation, a subsidiary of Broan-NuTone, notified 8 New Hampshire residents of a data breach involving a malicious script on its website. The script, active from July 20 to August 10, 2023, targeted consumer personal and financial information. Zephyr removed the script, engaged its hosting provider, and offered credit monitoring via Experian.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_f5192ba0bba5bfcdMaine State AGfiled 2024-01-17Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/broan-nutone-zephyr-ventilation-20240117.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 17, 2024
- Raw hash
- 7596ea7d6bc34058e139945ff6a8496ba74c26236be3d64b254576256c4000fc
Reporting entity
- Name
- Broan-NuTone LLCnorm: broan nutone
Victim entity
- Name
- Zephyr Ventilationnorm: zephyr ventilation
Incident
- Discovered
- Aug 1, 2023
- Materiality determined
- —
- Notification sent
- Jan 17, 2024
- Affected individuals
- 8
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 weeks(169 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.