Tonneson & Company, PC
bd_6179866e2d1fee36 · schema v1 · pii pii-v1
Full breach record for Tonneson & Company, PC →Tonneson & Company, PC notified the NH Attorney General of a data security incident involving its third-party payroll vendor, Paycor. The incident stemmed from a MOVEit zero-day vulnerability exploited by attackers. Tonneson learned in December 2023 that employee data was impacted. Written notice was sent on April 25, 2024, to 12 New Hampshire residents, offering credit monitoring and identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 1, 2023
Discovered
Apr 25, 2024
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Massachusetts State AGbd_2074db8e76da2e7b2024-04-25Verified
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.