HackingVulnerability ExploitCapture Stored DataZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedTargetedPIIIDENTITY_BASICHEALTH_BASICCVE-2023-0669MediumContained
NationsBenefits Holdings, LLC
bd_7a3042e338cc1200 · schema v1 · pii pii-v1
Full breach record for NationsBenefits Holdings, LLC →NationsBenefits Holdings, LLC reported a security incident resulting from a zero-day vulnerability (CVE-2023-0669) in Fortra's GoAnywhere MFT software. The incident occurred on Jan 30, 2023, and was discovered on Feb 7, 2023. Personal and health information of approximately 7,030 New Hampshire residents was impacted. NationsBenefits took the server offline, engaged forensic investigators, notified the FBI, and provided 24 months of credit monitoring to affected individuals.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1b538b7a6b069a1eVermont State AGfiled 2023-04-13Verified
- bd_27eb698b3f802e52Montana State AGfiled 2023-04-13Candidate
- bd_e00425fe19d51b10Delaware State AGfiled 2023-04-13Verified
- bd_5cf8474b7cde8f07California State AGfiled 2023-04-14(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 22d gap
- bd_90ff9cd7813fad7cOregon State AGfiled 2023-05-01(18d gap)Verified
- bd_be7b07047f2e066aMaine State AGfiled 2023-05-05(22d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/nationsbenefits-holdings-20230413.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 13, 2023
- Raw hash
- 199f3f65cbfd5c1c1dc2ff857f76f3d6531d7b8fad52cd1a149c4534ec9d39f0
Reporting entity
- Name
- NationsBenefits Holdings, LLCnorm: nationsbenefits holdings
Victim entity
- Name
- NationsBenefits Holdings, LLCnorm: nationsbenefits holdings
Incident
- Discovered
- Feb 7, 2023
- Materiality determined
- Feb 13, 2023
- Notification sent
- Apr 13, 2023
- Affected individuals
- 7,030
- Data types
- PIIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation (FBI)Providing required notices to the H.H.S. Office for Civil RightsProviding required notices to prominent media outletsProviding required notices to consumer reporting agenciesProviding required notices to certain state agencies
- Third party
- via Fortra, LLC
- Initial access
- exploit_public_facing
- CVE references
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.