DisclosureLens
HackingProfessional ServicesProfessional ServicesStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedGovernment IDIdentity (basic)MediumContained

Tonneson & Company, PC

bd_6179866e2d1fee36 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 1, 2023

Filed

Apr 25, 2024

To disclose

21 weeks

Affected

12state residents only

Linked

2 filings

Confidence

67%
Full breach record for Tonneson & Company, PC

Tonneson & Company, PC notified the NH Attorney General of a data security incident involving its third-party payroll vendor, Paycor. The incident stemmed from a MOVEit zero-day vulnerability exploited by attackers. Tonneson learned in December 2023 that employee data was impacted. Written notice was sent on April 25, 2024, to 12 New Hampshire residents, offering credit monitoring and identity protection services.

Incident timeline

discovery → filing · 21 weeks / 146 days

Dec 1, 2023

Discovered

Apr 25, 2024

Filed

vs. sector median

+3 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Massachusetts State AGApr 25 · first
New Hampshire State AGApr 25 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.