MalwareRansomwareRansom DemandedRansom PaidData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Horizon Actuarial
bd_60c050db559ca233 · schema v1 · pii pii-v1
Full breach record for Horizon Actuarial →Soft Drink & Brewery Workers Union Local 812 Retirement Fund reported a data breach involving its vendor, Horizon Actuarial Services, LLC. The incident, discovered on January 13, 2022, involved unauthorized access to Horizon's servers between November 10-11, 2021. The attacker claimed to have stolen Social Security Numbers, names, and dates of birth of 6 New Hampshire residents. Horizon paid a ransom to the attacker and provided credit monitoring services to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_57e4879b692c8a62New Hampshire State AGfiled 2022-03-22(2d gap)Candidate
- bd_acc2dcb63f662ce2New Hampshire State AGfiled 2022-03-22(2d gap)Verified
- bd_0f74d080348e1e13Delaware State AGfiled 2022-04-11(18d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/soft-drink-brewery-workers-local-812-retirement-fund-20220324.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 24, 2022
- Raw hash
- f53dd2d5e1d219175b97e6fabe1aa03187c73988e061f2087f43f0ee2cc974c1
Reporting entity
- Name
- Soft Drink & Brewery Workers Union Local 812 Retirement Fundnorm: soft drink brewery workers union local 812 retirement
Victim entity
- Name
- Horizon Actuarialnorm: horizon actuarial
- Domain
- horizonactuarial.com
Incident
- Discovered
- Jan 13, 2022
- Materiality determined
- —
- Notification sent
- Mar 25, 2022
- Affected individuals
- 6
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- provided notice to the FBI
- Initial access
- phishing_link
Compliance
- Time to disclose
- 10 weeks(70 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.