HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumActive
Krapf Group
bd_568291789eb998b0 · schema v1 · pii pii-v1
Full breach record for Krapf Group →The Krapf Group experienced a cybersecurity incident where an unauthorized actor accessed its network on or around November 17, 2020, and exfiltrated personal information including names, dates of birth, addresses, and Social Security numbers. The breach was discovered on November 23, 2020. The company engaged forensic investigators and is offering one year of Experian IdentityWorks monitoring to affected individuals. The investigation was ongoing as of the January 15, 2021 notification date.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_981108341a7fd56cHHS OCRfiled 2021-01-19(4d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/01/Krapf-Sample-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 15, 2021
- Raw hash
- 4e72319f46bcbd3d27e642372b6e550f25224573fdca09e1702b7649c0f64a5a
Reporting entity
- Name
- Krapf Groupnorm: krapf group
Victim entity
- Name
- Krapf Groupnorm: krapf group
Incident
- Discovered
- Nov 23, 2020
- Materiality determined
- —
- Notification sent
- Jan 15, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.