HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedTargetedPIIIDENTITY_BASICLowContained
Constellation
bd_5956b91aa79a4b36 · schema v1 · pii pii-v1
Full breach record for Constellation →Constellation Software Inc. reported an unauthorized third-party access to its network between Feb 27 and Apr 3, 2023. The attacker viewed and took files containing personal information. Constellation engaged forensic investigators, notified law enforcement, isolated systems, and offered 12 months of credit monitoring to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b9631555636ec7d9Maine State AGfiled 2023-05-25Candidate
- bd_b6cc684d4d89fc1aVermont State AGfiled 2023-05-12(13d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/constellation-software-20230525.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 25, 2023
- Raw hash
- 42357589463be2aba488213c5b9372e46b80631cbd776f0dabc74f25d6a1410c
Reporting entity
- Name
- Constellationnorm: constellation
- Domain
- constellation.com
Victim entity
- Name
- Constellationnorm: constellation
- Domain
- constellation.com
Incident
- Discovered
- Apr 28, 2023
- Materiality determined
- May 2, 2023
- Notification sent
- May 25, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.