HackingIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Maplesoft
bd_3639d71c4bfe2d08 · schema v1 · pii pii-v1
Full breach record for Maplesoft →Maplesoft (Waterloo Maple Inc.) notified New Hampshire AG of a data breach affecting 8 NH customers. A malicious script was inserted into the online store on or around July 21, 2021, capturing names, addresses, emails, and credit card details. Discovered April 7, 2022, the script was removed, the site shut down, and passwords reset. Notifications were sent to affected users.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b5fdcdd472b97805Montana State AGfiled 2022-04-09(3d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/maplesoft-20220412.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 12, 2022
- Raw hash
- 790e9e940b01429f03ff66ad12577950231aa15182f19428da81c8d59fe8191c
Reporting entity
- Name
- Waterloo Maple Inc.norm: waterloo maple
- Domain
- maplesoft.com
Victim entity
- Name
- Maplesoftnorm: maplesoft
- Domain
- maplesoft.com
Incident
- Discovered
- Apr 7, 2022
- Materiality determined
- —
- Notification sent
- Apr 12, 2022
- Affected individuals
- 8
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 days(5 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.