MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighContained
PurFoods Holdings, LLC
bd_71f79a87b2334fa2 · schema v1 · pii pii-v1
Full breach record for PurFoods Holdings, LLC →PurFoods, LLC notified New Hampshire residents on August 25, 2023, of a cyberattack occurring between January 16 and February 22, 2023. The incident involved ransomware encryption and potential data exfiltration. Approximately 1,297 NH residents were affected, with data including names, SSNs, DOBs, and health insurance IDs. PurFoods engaged third-party specialists, notified law enforcement and HHS, and provided credit monitoring via Kroll.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_5922a07dfc32ec37Maine State AGfiled 2023-08-25Verified
- bd_c2d1d182956f3f11Montana State AGfiled 2023-08-25Candidate
- bd_d13fdb19999e965eCalifornia State AGfiled 2023-08-25Verified
- bd_e470432f0b0b5928Vermont State AGfiled 2023-08-25Verified
Show 2 more filings ↓Show fewer ↑up to 6d gap
- bd_eaf838850645f5a2Washington State AGfiled 2023-08-25Verified
- bd_b19ff7b969be846dOregon State AGfiled 2023-08-31(6d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/purfoods-20230825.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 25, 2023
- Raw hash
- 4db620faf5df427c55473ad26309be6415c36b8bf46aef15f5d76201da5fa990
Reporting entity
- Name
- PurFoods Holdings, LLCnorm: purfoods holdings
Victim entity
- Name
- PurFoods Holdings, LLCnorm: purfoods holdings
Incident
- Discovered
- Feb 22, 2023
- Materiality determined
- —
- Notification sent
- Aug 25, 2023
- Affected individuals
- 1,297
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notified federal law enforcement regarding the eventproviding written notice of this incident to relevant state regulatorsnotifying the U.S. Department of Health and Human Services
Compliance
- Time to disclose
- 26 weeks(184 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.