HackingDelayed DiscoveryIDENTITY_BASICLowContained
The Cannon Corporation
bd_47c8afecbf0e0a57 · schema v1 · pii pii-v1
Full breach record for The Cannon Corporation →The Cannon Corporation (dba CannonDesign) notified consumers of a cybersecurity incident where an unauthorized third party accessed its network between Jan 19-25, 2023. Suspicious activity was detected on Jan 25, 2023. The investigation determined that names and other personal information were accessed. The company offered 24 months of credit monitoring. 26 Rhode Island residents were explicitly identified as impacted.
Vermont clock✗ VT AG >45 bday19 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by avoslocker about this victim predates this filing by 555 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_254fc6798c6e3f3aMontana State AGfiled 2024-08-19Candidate
- bd_6075ef2eac55c60aNew Hampshire State AGfiled 2024-08-19Candidate
- bd_ce1fa2f5343ac702California State AGfiled 2024-08-19Verified
- bd_5e25aa73e9170528New Hampshire State AGfiled 2024-09-16(28d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-08-19-cannon-corporation-dba-cannondesign-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 19, 2024
- Raw hash
- 949612a3ac47152884c60869b8fff33a2b0b2748bacbdf4f034e3cab57bef99f
Reporting entity
- Name
- The Cannon Corporationnorm: the cannon
- Domain
- cannondesign.com
Victim entity
- Name
- The Cannon Corporationnorm: the cannon
- Domain
- cannondesign.com
Incident
- Discovered
- Jan 25, 2023
- Materiality determined
- —
- Notification sent
- Aug 19, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notifying state regulators, as required
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 months(572 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.