HackingStolen CredentialsCapture Stored DataCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumActive
Ultrafab, Inc.
bd_4eaab36cb34ae4dc · schema v1 · pii pii-v1
Full breach record for Ultrafab, Inc. →Ultrafab, Inc. reported a data security incident to the New Hampshire Attorney General on May 8, 2024. The company became aware of unusual activity on April 9, 2024, leading to unauthorized access to files containing PII and PHI of current and former employees. Three New Hampshire residents were notified. Ultrafab engaged forensic experts, notified the FBI, and provided credit monitoring services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ultrafab-20240508.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 8, 2024
- Raw hash
- ba52ef9eca1e660269efdfbfabd31f174294f93f35271d242050f8c63e0e6199
Reporting entity
- Name
- Ultrafab, Inc.norm: ultrafab
- Domain
- ultrafab.com
Victim entity
- Name
- Ultrafab, Inc.norm: ultrafab
- Domain
- ultrafab.com
Incident
- Discovered
- Apr 9, 2024
- Materiality determined
- Apr 25, 2024
- Notification sent
- May 8, 2024
- Affected individuals
- 3
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.