MalwareRansomwareData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Kitestring Consulting, Inc.
bd_6dd27b8173ff41c3 · schema v1 · pii pii-v1
Full breach record for Kitestring Consulting, Inc. →Kitestring Consulting, Inc. notified the New Hampshire Attorney General of a data event involving a third-party payroll vendor. On February 1, 2021, Kitestring detected suspicious activity where an unauthorized actor accessed the vendor's server and attempted to encrypt files. One NH resident was affected. Data potentially exposed included names, SSNs, driver's license numbers, and bank account info. Kitestring offered one year of credit monitoring via Kroll.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/kitestring-consulting-20210315.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 15, 2021
- Raw hash
- 212c93a01f536585abd6d44b9d1b04be567e1487af3f394f5d53dccad04fc8b5
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Kitestring Consulting, Inc.norm: kitestring consulting
Incident
- Discovered
- Feb 1, 2021
- Materiality determined
- —
- Notification sent
- Mar 11, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.