HackingCustomer Data InvolvedData ExfiltratedPIIIDENTITY_BASICLowContained
Prentke Romich Company
bd_347c6a13e03a974d · schema v1 · pii pii-v1
Full breach record for Prentke Romich Company →Prentke Romich Company dba PRC-Saltillo notified affected individuals of a data breach occurring between August 13 and August 21, 2024. The company detected suspicious activity on August 21, 2024, and determined that an unauthorized actor copied files containing personal information. PRC-Saltillo secured systems, launched an investigation, and is offering complimentary credit monitoring and identity theft protection services through Experian.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_96781319d3fe8f86Leak Sitefogfiled 2024-09-18(7d gap)Verified
Regulatory filings (6) · sorted by filing gap
- bd_05a162b64afeee2cIndiana State AGfiled 2024-09-12Verified
- bd_09af3448d15112fbMontana State AGfiled 2024-09-12Verified by operator
- bd_6b1745cca9569fa6Vermont State AGfiled 2024-09-12Verified
- bd_3534a44b64948843HHS OCRfiled 2024-09-25(13d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 13d gap
- bd_848e7cd93d7ca5ecCalifornia State AGfiled 2024-09-25(13d gap)Verified
- bd_89db2b0c000a38ceWashington State AGfiled 2024-09-25(13d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/prentke-romich-prc-saltillo-20240912.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 12, 2024
- Raw hash
- 86d10f5a322c1d478f7cda529b7d87fbbe86172872a87ecd7369381ea982a5ab
Reporting entity
- Name
- Prentke Romich Companynorm: prentke romich
- Domain
- prentrom.com
Victim entity
- Name
- Prentke Romich Companynorm: prentke romich
- Domain
- prentrom.com
Incident
- Discovered
- Aug 21, 2024
- Materiality determined
- Sep 3, 2024
- Notification sent
- Sep 12, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.