HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Tonneson & Company, PC
bd_6179866e2d1fee36 · schema v1 · pii pii-v1
Full breach record for Tonneson & Company, PC →Tonneson & Company, PC notified the NH Attorney General of a data security incident involving its third-party payroll vendor, Paycor. The incident stemmed from a MOVEit zero-day vulnerability exploited by attackers. Tonneson learned in December 2023 that employee data was impacted. Written notice was sent on April 25, 2024, to 12 New Hampshire residents, offering credit monitoring and identity protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed12 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/tonneson-20240425.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 25, 2024
- Raw hash
- eea3ca741bdda8ce52fd798d6f288b4c921b91cc1a1150fd9f5b6e68abdf395d
Reporting entity
- Name
- Tonneson & Company, PCnorm: tonneson
Victim entity
- Name
- Tonneson & Company, PCnorm: tonneson
Incident
- Discovered
- Dec 1, 2023
- Materiality determined
- —
- Notification sent
- Apr 25, 2024
- Affected individuals
- 12
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- Partner
- Initial access
- supply_chain
Compliance
- Time to disclose
- 21 weeks(146 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.