HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Comprehensive Health Services
bd_71314889a3bf0e51 · schema v1 · pii pii-v1
Full breach record for Comprehensive Health Services →Comprehensive Health Services (CHS) notified the New Hampshire Attorney General of a data security incident affecting one NH resident. CHS detected unusual activity on September 30, 2020, following fraudulent wire transfers, indicating credential compromise. The investigation concluded on November 3, 2021, that personal information (names, SSNs) of a limited number of individuals employed by customer Anchor QEA, LLC was accessed. Notification was sent on January 20, 2022, offering credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_119a2929b9bc9c2bNew Hampshire State AGfiled 2022-02-15(26d gap)Candidate
- bd_3287d556e934a6bdNew Hampshire State AGfiled 2022-03-15(54d gap)Verified
- bd_7b6e34bd70633badMaine State AGfiled 2022-03-16(55d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/comprehensive-health-services-20220120.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 20, 2022
- Raw hash
- 1f25303668e0308d38a6d8f1282a216e6a1da09078ba5a3ffd8a52c7c7463ee1
Reporting entity
- Name
- Comprehensive Health Servicesnorm: comprehensive health
Victim entity
- Name
- Comprehensive Health Servicesnorm: comprehensive health
Incident
- Discovered
- Sep 30, 2020
- Materiality determined
- —
- Notification sent
- Jan 20, 2022
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 months(477 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.