Andesa
bd_7515e55209419011 · schema v1 · pii pii-v1
Full breach record for Andesa →Andesa Services, Inc. notified the New Hampshire Attorney General of a cybersecurity incident involving the MOVEit Transfer server. An actor exploited vulnerabilities to access the server between May 30 and May 31, 2023, and exfiltrated data. Andesa Services notified 14 New Hampshire residents on October 23, 2023, offering credit monitoring through Experian. The incident involved personal information and government identifiers.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
May 31, 2023
Discovered
Oct 25, 2023
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitedispossessorbd_bee424cd2ef287e62023-08-27 · +59dVerified by operator
- Leak Sitecl0pbd_387b6476cd49ce4c2023-06-23 · +124dVerified by operator
Regulatory filings (7) · sorted by filing gap
- Maine State AGbd_18f81f490bcf9b002023-10-25Verified by operator
- Massachusetts State AGbd_a6349629c1062e652023-10-25Verified by operator
- Montana State AGbd_6c4814cd840b05072023-10-23 · +2dVerified by operator
- Indiana State AGbd_6d55c181d2029fd52023-10-23 · +2dVerified
Show 3 more filings ↓Show fewer ↑up to 6d gap
- California State AGbd_871d7add6a1eb5452023-10-23 · +2dVerified by operator
- Vermont State AGbd_d272e85e64f9ed582023-10-23 · +2dVerified by operator
- New Hampshire State AGbd_18472c95d93c96652023-10-31 · +6dVerified by operator
Filing propagation · 8 filings · 7 states
View merged incident ↗Pattern: first filing Oct 23 (MT), last Oct 31 (NH) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.