HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Northern Jet
bd_6398be8b58a21211 · schema v1 · pii pii-v1
Full breach record for Northern Jet →Northern Jet Management notified the New Hampshire Attorney General of a security incident involving its third-party vendor, Avianis. Between December 6-7, 2020, an unauthorized person exploited a vulnerability in a Microsoft Azure database maintained by Avianis to exfiltrate data. Northern Jet learned on February 4, 2021, that the personal information of one New Hampshire resident (name, driver's license, passport) was copied. Northern Jet mailed a notification letter on March 11, 2021, offering one year of credit monitoring via Equifax.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/northern-jet-management-20210312.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 12, 2021
- Raw hash
- dfbd19a9538ca536512671def0bfdb906573fb2939f5e896baad50a1955d10be
Reporting entity
- Name
- Northern Jetnorm: northern jet
- Domain
- northernjet.com
Victim entity
- Name
- Northern Jetnorm: northern jet
- Domain
- northernjet.com
Incident
- Discovered
- Feb 4, 2021
- Materiality determined
- —
- Notification sent
- Mar 11, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Third party
- via Avianis
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.