DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitCustomer Data InvolvedIdentity (basic)LowContained

CUSO Financial Services, L.P.

bd_7dfd4f2b42eb5c01 · schema v1 · pii pii-v1

Severity

Low

Discovered

Oct 20, 2023

Filed

Feb 16, 2024

To disclose

17 weeks

Affected

Not disclosed

Linked

7 filings

Confidence

65%
Full breach record for CUSO Financial Services, L.P.5 incidents on file

CUSO Financial Services, LP notified the California AG of an incident where an unauthorized party exploited a vulnerability in Barracuda Networks email application to access historical emails and attachments. The breach occurred on July 5, 2022, and was discovered on October 20, 2023. Affected data includes names and other personal information. The company closed the vulnerability, reported the incident to federal law enforcement, and offered credit monitoring services.

Incident timeline

undetected · 472 days
discovery → filing · 17 weeks / 119 days

Jul 5, 2022

Begins

Oct 20, 2023

Discovered

Feb 16, 2024

Filed

vs. sector median

+9 wks slower

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filings

Filing propagation · 7 filings · 7 states

View merged incident ↗
Massachusetts State AGFeb 16 · first
Vermont State AGFeb 16 · first
Indiana State AGFeb 16 · first
Montana State AGFeb 16 · first
Maine State AGFeb 16 · first
New Hampshire State AGFeb 16 · first
California State AGFeb 16 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.