DisclosureLens
HackingProfessional ServicesProfessional ServicesVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Government IDMediumContained

The Reynolds and Reynolds Company

bd_451e9e03c7a73014 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 30, 2023

Filed

Jan 16, 2024

To disclose

7 weeks

Affected

1state residents only

Confidence

66%
Full breach record for The Reynolds and Reynolds Company

The Reynolds Company notified the NH Attorney General of a third-party data breach involving vendor Paycor's MOVEit transfer platform. Unauthorized access occurred around May 31, 2023, discovered by Paycor on Nov 30, 2023. One NH resident's name and SSN were exposed. Reynolds notified the individual on Jan 16, 2024, offering one year of Kroll identity monitoring.

Incident timeline

undetected · 183 days
discovery → filing · 7 weeks / 47 days

May 31, 2023

Begins

Nov 30, 2023

Discovered

Jan 16, 2024

Filed

vs. sector median

11 wks faster

Part of Paycor supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.