DisclosureLens
HackingFinancial ServicesFinanceStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDMediumContained

CENTRAL SECURITIES CORPORATION

bd_3e34accc2e6a85e7 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 20, 2024

Filed

Sep 30, 2024

To disclose

19 weeks

Affected · nationwide

6243 in this filing

Linked

5 filings

Confidence

66%
Full breach record for CENTRAL SECURITIES CORPORATION

Central Securities Corporation, a closed-end investment management company, disclosed a cybersecurity incident where an unauthorized third party accessed internal systems via a compromised vendor account between April 17 and May 20, 2024. The breach exposed personal information including names, SSNs, and government IDs of 624 individuals. The company engaged forensic experts, notified law enforcement, terminated vendor access, and offered 24 months of credit monitoring.

Maine clockDiscovered May 20, 2024Filed with AG Sep 30, 2024133d ME AG >90d19 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 33 days
discovery → filing · 19 weeks / 133 days

Apr 17, 2024

Begins

May 20, 2024

Discovered

Sep 30, 2024

Filed

vs. sector median

+10 wks slower

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Indiana State AGSep 30 · first
Massachusetts State AGSep 30 · first
New Hampshire State AGSep 30 · first
Maine State AGSep 30 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.