DisclosureLens
HackingTransportation & LogisticsTransportationVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedGovernment IDFinancial accountMediumActive

Aero Charter, Inc.

bd_341e008ae7a8f1a2 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 6, 2020

Filed

Mar 1, 2021

To disclose

12 weeks

Affected

1state residents only

Confidence

66%
Full breach record for Aero Charter, Inc.2 incidents on file

Aero Charter, Inc. notified the NH Attorney General that its software provider, Avianis Systems, LLC, suffered a data breach on December 6, 2020. An intruder exploited a vulnerability in a Microsoft Azure Cloud file storage container configuration to illegally download document files. The breach affected one New Hampshire resident. Compromised data included passport information, state-issued ID, federal pilot license, driver’s license, and payment card information. Avianis contained the incident within 24 hours and is working with forensic investigators and law enforcement. Aero Charter is offering 12 months of complimentary identity theft protection.

Incident timeline

discovery → filing · 12 weeks / 85 days

Dec 6, 2020

Begins

Dec 6, 2020

Discovered

Mar 1, 2021

Filed

Part of Avianis supply-chain incident (2021) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.