HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)FINANCIAL_ACCOUNTLowActive
Symantec Corporation
bd_7b6f254948c9636a · schema v1 · pii pii-v1
Full breach record for Symantec Corporation →Symantec Corporation notified the New Hampshire Attorney General of a potential security incident involving a call center vendor. A UK media outlet alleged that credit card numbers of three UK residents were purchased from the call center. Symantec sent notification to one New Hampshire resident out of an abundance of caution, provided one year of identity protection services, and is investigating with law enforcement. No evidence of US resident compromise was found.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/symantec-20090324.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 24, 2009
- Raw hash
- 2cd760903377e3c9ae29a0bac71e83ca57832abf0054368dd15a20d8445ad7f7
Reporting entity
- Name
- Symantec Corporationnorm: symantec
Victim entity
- Name
- Symantec Corporationnorm: symantec
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Mar 25, 2009
- Affected individuals
- 1
- Data types
- FINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Kelly A. Ayotte
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.