DisclosureLens
HackingProfessional ServicesProfessional ServicesCustomer Data InvolvedIdentity (basic)Government IDMediumContained

Dun & Bradstreet Holdings, Inc.

bd_3467e3167f025813 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Oct 28, 2013

To disclose

Affected

Not disclosed

Linked

2 filings

Confidence

65%
Full breach record for Dun & Bradstreet Holdings, Inc.

Dun & Bradstreet disclosed a cyberattack occurring between March and April 2013 that resulted in unauthorized access to a commercial information database. The incident potentially exposed personal information including names and business identification numbers that may have been Social Security Numbers. The company stated the incident is contained and offered 12 months of identity protection services via AllClear ID.

Incident timeline

Mar 1, 2013

Begins

Oct 28, 2013

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
New Hampshire State AGOct 25 · first
California State AG+3d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.