DisclosureLens
HackingProfessional ServicesProfessional ServicesTargetedCustomer Data InvolvedIdentity (basic)Government IDMediumContained

Dun & Bradstreet Holdings, Inc.

bd_7f463293b7ba1722 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Oct 25, 2013

To disclose

Affected

277state residents only

Linked

2 filings

Confidence

66%
Full breach record for Dun & Bradstreet Holdings, Inc.

Dun & Bradstreet notified the New Hampshire Attorney General of a criminal cyberattack occurring in March-April 2013. The incident potentially exposed the names and SSNs (as business IDs) of 277 NH residents. D&B is working with law enforcement, has notified credit bureaus, and is offering 12 months of credit monitoring via AllClear ID. The incident is considered contained.

Incident timeline

Mar 1, 2013

Begins

Oct 25, 2013

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
New Hampshire State AGOct 25 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.