HackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumActive
LOWER, LLC
bd_71783a8d00bb9579 · schema v1 · pii pii-v1
Full breach record for LOWER, LLC →Lower LLC, a professional services firm, disclosed a data event where an unauthorized actor accessed its network and exfiltrated files containing names, Social Security numbers, dates of birth, driver's license numbers, and financial account numbers. The incident occurred between Dec 10-14, 2021, and was discovered on Dec 14, 2021. This supplemental notice covers 812 Delaware residents, bringing the total notified to 812. Lower engaged forensic specialists, notified law enforcement, and provided credit monitoring via Experian.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_625459f82668599bCalifornia State AGfiled 2022-10-06Candidate
- bd_7df47a2b4d3e875bDelaware State AGfiled 2022-10-06Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/10/Lower-LLC-DE-Supplemental-Notice-of-Data-Event.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 6, 2022
- Raw hash
- ea5ac3e3dfde301968dc5af471c70013ff138bb8cdd200edddec86ba58e57a40
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- LOWER, LLCnorm: lower
Incident
- Discovered
- Dec 14, 2021
- Materiality determined
- —
- Notification sent
- Oct 6, 2022
- Affected individuals
- 812
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notifying regulatory authorities as required by law
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 42 weeks(296 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.