HackingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICLowContained
The Cannon Corporation
bd_5e25aa73e9170528 · schema v1 · pii pii-v1
Full breach record for The Cannon Corporation →Cannon Design Corporation reported a supplemental breach notice to New Hampshire residents regarding unauthorized network access occurring between Jan 19-25, 2023. The incident affected 28 NH residents (plus others in RI). Data involved was name and [Extra1]. The company notified law enforcement, offered credit monitoring, and is implementing additional security training.
Leak gap clock✗ Leak >180d20 months discovery → filing
This filing is one of 5 about the same incident.View merged incident
A leak claim by avoslocker about this victim predates this filing by 583 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_254fc6798c6e3f3aMontana State AGfiled 2024-08-19(28d gap)Candidate
- bd_47c8afecbf0e0a57Vermont State AGfiled 2024-08-19(28d gap)Verified
- bd_6075ef2eac55c60aNew Hampshire State AGfiled 2024-08-19(28d gap)Candidate
- bd_ce1fa2f5343ac702California State AGfiled 2024-08-19(28d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cannon-design-20240916.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 16, 2024
- Raw hash
- 14652cc58cc3384056848da1ebc578c63929a38912264bbfeb44d0e00f456931
Reporting entity
- Name
- The Cannon Corporationnorm: the cannon
- Domain
- cannondesign.com
Victim entity
- Name
- The Cannon Corporationnorm: the cannon
- Domain
- cannondesign.com
Incident
- Discovered
- Jan 25, 2023
- Materiality determined
- May 3, 2024
- Notification sent
- Sep 16, 2024
- Affected individuals
- 28
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal law enforcementProviding written notice of this incident to relevant state regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 20 months(600 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.