HackingVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedDownstream VictimsPIIIDENTITY_BASICIDENTITY_GOVERNMENTCriticalContained
CHSPSC, LLC
bd_2bde52fe641f21a1 · schema v1 · pii pii-v1
Full breach record for CHSPSC, LLC →CHSPSC, LLC filed a supplemental notice regarding the Fortra GoAnywhere file transfer service breach. The incident occurred Jan 28-30, 2023, exploiting a previously unknown vulnerability. CHSPSC discovered the impact on Feb 2, 2023. 1,173,555 individuals affected, including 109 NH residents. Data types include PII and government IDs. Remediation included patching, rebuilding platform, and offering credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_fb0d0d6b9ca586f2Delaware State AGfiled 2023-03-06(46d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/chspsc-20230421.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2023
- Raw hash
- 2cbe3b7c4c842c58103ec441d02eae654e24f6ff2e8c3bc77f3a76dcfeec7aee
Reporting entity
- Name
- CHSPSC, LLCnorm: chspsc
Victim entity
- Name
- CHSPSC, LLCnorm: chspsc
Incident
- Discovered
- Feb 2, 2023
- Materiality determined
- —
- Notification sent
- Mar 24, 2023
- Affected individuals
- 1,173,555
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified FBINotified CISA
- Third party
- via Fortra, LLC
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.