HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICLowContained
EFS Advisors LLC
bd_34c7a063a56e0945 · schema v1 · pii pii-v1
Full breach record for EFS Advisors LLC →EFS Advisors LLC reported a data security incident detected on February 22, 2024, involving a zero-day vulnerability exploited via software used by an external IT provider. The breach potentially exposed personal information of 6 New Hampshire residents. EFS engaged forensic investigators, worked with law enforcement, and offered credit monitoring services to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_31960f63d3ee1d59Montana State AGfiled 2024-05-23Candidate
- bd_e97465459911133fMaine State AGfiled 2024-05-23Verified
- bd_f72c0652e062f3dbIndiana State AGfiled 2024-05-23Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/efs-advisors-20240523.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 23, 2024
- Raw hash
- 8fa4e7ce5b57450ee0b70f5aca70cb5f7f056b19ab15cf45db3b45cbdd8f00fa
Reporting entity
- Name
- EFS Advisors LLCnorm: efs advisors
Victim entity
- Name
- EFS Advisors LLCnorm: efs advisors
Incident
- Discovered
- Feb 22, 2024
- Materiality determined
- —
- Notification sent
- May 23, 2024
- Affected individuals
- 6
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(91 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.