HackingCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
CommuteAir •
bd_719293061db8f4cb · schema v1 · pii pii-v1
Full breach record for CommuteAir • →CommuteAir, LLC notified the New Hampshire Attorney General on January 24, 2023, of a cybersecurity incident discovered on January 17, 2023. A security researcher identified an unsecured development server containing employee PII, including names, DOBs, addresses, and partial SSNs. Four New Hampshire residents were affected. CommuteAir took the server offline, reset credentials, engaged Mandiant for forensic analysis, and reported the incident to CISA.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3902fc58e6d17f7bMaine State AGfiled 2023-01-24Verified
- bd_f97d3e23762591f8Montana State AGfiled 2023-01-23(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/commuteair-20230124.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 24, 2023
- Raw hash
- bb52b8526ba0192b8b04c709247f1305c4406010a8ebc518faa91c01c7082190
Reporting entity
- Name
- CommuteAir •norm: commuteair
- Domain
- commuteair.com
Victim entity
- Name
- CommuteAir •norm: commuteair
- Domain
- commuteair.com
Incident
- Discovered
- Jan 17, 2023
- Materiality determined
- —
- Notification sent
- Jan 24, 2023
- Affected individuals
- 4
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified the Office of the Attorney General of New HampshireReported the exposure to the Cybersecurity and Infrastructure Security Agency (CISA)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.