HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedTargetedPIIIDENTITY_BASICMediumContained
Carvin Audio
bd_298585b51b9c0d49 · schema v1 · pii pii-v1
Full breach record for Carvin Audio →Carvin Software, LLC reported a data event where unauthorized access occurred between Feb 22 and Mar 9, 2023. The company identified unusual activity on Mar 9, 2023, and determined files were copied without authorization. PII of 2,334 New Hampshire residents was affected. Carvin notified law enforcement, isolated systems, and offered 12 months of credit monitoring.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_1a019f0dc61bda8dMontana State AGfiled 2023-05-02(7d gap)Candidate
- bd_607315800f92712cMaine State AGfiled 2023-05-02(7d gap)Verified
- bd_8d65e705d3015f8dOregon State AGfiled 2023-05-02(7d gap)Verified
- bd_b7d614e4113908f9Washington State AGfiled 2023-05-02(7d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 10d gap
- bd_d533a09a64f4a304California State AGfiled 2023-05-02(7d gap)Verified
- bd_f4854483539e0301Delaware State AGfiled 2023-05-02(7d gap)Verified
- bd_e3da1816f9fc0621California State AGfiled 2023-05-17(8d gap)Verified
- bd_a5615bf8e5598a2bCalifornia State AGfiled 2023-05-19(10d gap)Verified
- bd_b9b266fe06fc8de9Vermont State AGfiled 2023-05-19(10d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/carvin-software-20230509.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 9, 2023
- Raw hash
- 4552701f828c1055441581284ca43b5fc1ea7d7e69a9349e671a0371fe062dcf
Reporting entity
- Name
- Carvin Audionorm: carvin audio
- Domain
- carvinaudio.com
Victim entity
- Name
- Carvin Audionorm: carvin audio
- Domain
- carvinaudio.com
Incident
- Discovered
- Mar 9, 2023
- Materiality determined
- Mar 27, 2023
- Notification sent
- Apr 18, 2023
- Affected individuals
- 2,334
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided written notice of this incident to relevant state regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.