HackingData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Canadian Standards Association
bd_41a59e48ca01b25e · schema v1 · pii pii-v1
Full breach record for Canadian Standards Association →CSA Group (Canadian Standards Association) notified the New Hampshire Attorney General of a security breach affecting its Learning Centre web server in Toronto. The breach, discovered on December 20, 2027, potentially exposed names, addresses, and encrypted credit card data of customers. Only one New Hampshire resident was identified. Notifications were mailed on January 14, 2008. Forensic specialists were engaged, and affected sites were taken offline.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/csa-group-20080121.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 21, 2008
- Raw hash
- 66ace47a56b582fd985074f7fab6b2ef506ec6b0b5a93cbdf247af80c290318c
Reporting entity
- Name
- CSA NYCnorm: csa nyc
- Domain
- csa-nyc.org
Victim entity
- Name
- Canadian Standards Associationnorm: canadian standards
- Domain
- csagroup.org
Incident
- Discovered
- Dec 20, 2007
- Materiality determined
- —
- Notification sent
- Jan 14, 2008
- Affected individuals
- 1
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(32 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.