HackingData MishandlingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Direct Travel, Inc.
bd_5da64defbb2a3aec · schema v1 · pii pii-v1
Full breach record for Direct Travel, Inc. →Direct Travel, Inc. notified the New Hampshire Attorney General of a data security incident involving its cloud-service-provider. On April 28, 2021, an unauthorized individual acquired some of Direct Travel's data. The incident affected 4 New Hampshire residents, exposing dates of birth and/or passport numbers. Direct Travel retained forensic experts, enhanced network security, increased password complexity, and offered 12 months of complimentary identity monitoring via TransUnion. Notification letters were mailed on October 18, 2021.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_1fc29e5880d62102Montana State AGfiled 2021-10-18Candidate
- bd_871b7bbf367d1858Maine State AGfiled 2021-10-18Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/direct-travel-20211018.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 18, 2021
- Raw hash
- 765b768fde79b4daf5d9ef889c9d475fc3898be771327804b2384172072663c2
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- Direct Travel, Inc.norm: direct travel
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Oct 18, 2021
- Affected individuals
- 4
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.