HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedTargetedPIIIDENTITY_BASICMediumActive
BYTE FEDERAL, INC.
bd_49c9872bc3fd7264 · schema v1 · pii pii-v1
Full breach record for BYTE FEDERAL, INC. →Byte Federal Inc. reported a data breach discovered on November 18, 2024, where a bad actor exploited a third-party software vulnerability to gain unauthorized access to a server. The attacker encrypted data and acquired the encryption key. Approximately 58,000 customers nationwide were affected, including 182 in New Hampshire. Byte Federal shut down the platform, isolated the actor, reset credentials, and engaged forensic investigators. The investigation is ongoing.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_daeb670bbf3e3f52Oregon State AGfiled 2024-12-13Verified
- bd_0db76d11ece12d45Montana State AGfiled 2024-12-11(2d gap)Candidate
- bd_43871576fda33170California State AGfiled 2024-12-11(2d gap)Verified
- bd_8379555c684c474bMaine State AGfiled 2024-12-11(2d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 3d gap
- bd_bac8660828954ab9Vermont State AGfiled 2024-12-16(3d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/byte-federal-20241213.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 13, 2024
- Raw hash
- 9e6fbbceea58c4cdb52c23a9c33bf534c94aa7c0f07c5e347f7e6b38f2b656f8
Reporting entity
- Name
- BYTE FEDERAL, INC.norm: byte federal
Victim entity
- Name
- BYTE FEDERAL, INC.norm: byte federal
Incident
- Discovered
- Nov 18, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 58,000
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Reported the crime to the Sarasota County Sheriff’s Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.