Krapf Group
bd_39d18b4bf78d918d · schema v1 · pii pii-v1
Full breach record for Krapf Group →Krapf Group, a professional services firm, notified the New Hampshire Attorney General of a cybersecurity incident affecting one resident. On November 23, 2020, Krapf discovered an unauthorized actor gained access to its network between November 17-25, 2020. The actor downloaded ransomware files and exfiltrated data including payroll records and Social Security numbers. No encryption was executed. Krapf engaged forensic firm Crypsis, deployed endpoint security, and offered one year of credit monitoring to the affected individual.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 17, 2020
Begins
Nov 23, 2020
Discovered
Jan 19, 2021
Filed
vs. sector median
11 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- HHS OCRbd_981108341a7fd56c2021-01-19Verified
- Indiana State AGbd_2f53d9d984ed17262021-01-15 · +4dVerified
- Delaware State AGbd_568291789eb998b02021-01-15 · +4dVerified
- Massachusetts State AGbd_e7566369d4fab2792021-01-15 · +4dVerified
Show 1 more filing ↓Show fewer ↑up to 18d gap
- Illinois State AGbd_1b0e15d850a069f02021-01-01 · +18dCandidate
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Jan 19 (NH) — a 18-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.