HackingCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Steyr Arms USA
bd_3b30440de11539cd · schema v1 · pii pii-v1
Full breach record for Steyr Arms USA →Steyr Arms, Inc. notified the NH Attorney General of a data breach involving unauthorized access to customer and payment card information via a malicious Google Tag Manager code implanted on its website. The incident affected purchases made between June 15 and August 24, 2022. Ten New Hampshire residents were identified as impacted. Steyr Arms removed the code, engaged forensic experts, and offered one year of credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_192deead428caaefMaine State AGfiled 2022-12-21(6d gap)Candidate
- bd_f339d5920f75b70eMontana State AGfiled 2022-12-21(6d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/steyr-arms-20221215.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 15, 2022
- Raw hash
- a7240954e40c446a783aab4f423e0bb83d0ba4420f2e4433d5a3a1ac7714c6ca
Reporting entity
- Name
- Steyr Arms USAnorm: steyr arms usa
- Domain
- steyr-arms.us
Victim entity
- Name
- Steyr Arms USAnorm: steyr arms usa
- Domain
- steyr-arms.us
Incident
- Discovered
- Aug 1, 2022
- Materiality determined
- Nov 17, 2022
- Notification sent
- Dec 21, 2022
- Affected individuals
- 10
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(136 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.