HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
BlueLion, LLC
bd_6030b2e0c7941b90 · schema v1 · pii pii-v1
Full breach record for BlueLion, LLC →BlueLion, LLC, a New England HR company, notified the NH AG of a data security incident discovered on November 23, 2022. An unknown actor potentially accessed names, DOBs, and SSNs. BlueLion secured its network, engaged cybersecurity experts, and notified 43 NH residents on March 30, 2023, offering 12 months of credit monitoring and identity protection.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_04c71322a7fc54ebMaine State AGfiled 2023-03-30Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/bluelion-20230330.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 30, 2023
- Raw hash
- 1d3d632f0593a045bf931911bbf510f8b09b30d30381a25f7f329b8c69d08ef6
Reporting entity
- Name
- BlueLion, LLCnorm: bluelion
Victim entity
- Name
- BlueLion, LLCnorm: bluelion
Incident
- Discovered
- Nov 23, 2022
- Materiality determined
- —
- Notification sent
- Mar 30, 2023
- Affected individuals
- 43
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.