MalwareRansomwareData ExfiltratedCustomer Data InvolvedData EncryptedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
OSPREY PACKS, INC.
bd_70dc4adf76dcc3f1 · schema v1 · pii pii-v1
Full breach record for OSPREY PACKS, INC. →Osprey Packs, Inc. disclosed a cybersecurity incident in New Hampshire on August 27, 2013. The breach occurred on July 9, 2013, involving malware that encrypted files and exfiltrated customer data, including names, contact info, and credit card numbers. The company learned of the breach from a customer on August 7, notified affected individuals on August 13, and filed this notice with the NH Attorney General.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/osprey-packs-20130827.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 27, 2013
- Raw hash
- b319abd4cf35f126fd7d0cff66a833bb23a8f6fb19220142de876ee8380cd611
Reporting entity
- Name
- OSPREY PACKS, INC.norm: osprey packs
- Domain
- osprey.com
Victim entity
- Name
- OSPREY PACKS, INC.norm: osprey packs
- Domain
- osprey.com
Incident
- Discovered
- Aug 7, 2013
- Materiality determined
- —
- Notification sent
- Aug 13, 2013
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed security breach notification with New Hampshire Attorney General
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.