HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CAPULA INVESTMENT US LP
bd_2801f80d05bf9e45 · schema v1 · pii pii-v1
Full breach record for CAPULA INVESTMENT US LP →Capula Investment US LP notified the NH AG of a breach involving its payroll provider Paycor. An unauthorized third party exploited a zero-day vulnerability in Progress Software's MOVEit Transfer platform between May 29-30, 2023. The incident compromised personal information of one NH resident (CIUS personnel). Paycor conducted forensic analysis and notified Capula on Nov 30, 2023. Credit monitoring was offered.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/capula-investment-us-paycor-20240213.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 13, 2024
- Raw hash
- d98f4d3e4dbdfa34260e31ab172ffd0c916d753e7ae85225507ade3ada36c093
Reporting entity
- Name
- CAPULA INVESTMENT US LPnorm: capula investment us
Victim entity
- Name
- CAPULA INVESTMENT US LPnorm: capula investment us
Incident
- Discovered
- May 31, 2023
- Materiality determined
- Nov 30, 2023
- Notification sent
- Feb 13, 2024
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Third party
- via Paycor, Inc.
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 37 weeks(258 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.