Social EngineeringPhishingTargetedCustomer Data InvolvedData ExfiltratedIDENTITY_BASICLowContained
Rightway
bd_308c7046d18ebed4 · schema v1 · pii pii-v1
Full breach record for Rightway →Okta, Inc. notified the New Hampshire Attorney General of a data security incident involving its third-party vendor, Rightway Healthcare, Inc. A targeted SIM swap attack on a Rightway employee on September 23, 2023, led to unauthorized access to an eligibility census file. The incident impacted 16 New Hampshire residents, exposing personal information. Okta discovered the breach on October 5, 2023, and began notifying affected individuals on November 2, 2023, offering 24 months of credit monitoring and identity restoration services through Experian.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed16 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/okta-20231101.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 1, 2023
- Raw hash
- 820ffce3a0f30de68d0c319bdc002d5123b260183f9dc5c0f3b1d3dd1e8bdb83
Reporting entity
- Name
- OKTA, INC.norm: okta
Victim entity
- Name
- Rightwaynorm: rightway
- Domain
- rightwayhealthcare.com
Incident
- Discovered
- Oct 5, 2023
- Materiality determined
- —
- Notification sent
- Nov 2, 2023
- Affected individuals
- 16
- Data types
- IDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.