Comstar Technologies, LLC
bd_85177613717390c1 · schema v1 · pii pii-v1
Full breach record for Comstar Technologies, LLC →Comstar, LLC, a technology services provider, disclosed a data security event occurring between March 19 and 26, 2022. The incident involved unauthorized access to network files containing personal information of individuals associated with Comstar's business clients. Potentially affected data includes names, dates of birth, Social Security numbers, health insurance information, and medical assessment records. Comstar engaged third-party forensic experts, secured its network, and is offering credit monitoring services to affected individuals. The breach impacts residents across multiple US states, including California, New York, and Oregon.
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_b95db5904d98be34Maine State AGfiled 2022-06-30(16d gap)Verified
- bd_d818ee99f86b12ddCalifornia State AGfiled 2022-06-30(16d gap)Verified
- bd_7c3a134ab345e736HHS OCRfiled 2022-05-26(19d gap)Verified
- bd_7e62f29ad917b45dMontana State AGfiled 2022-05-25(20d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 69d gap
- bd_2302ead0876e2449Maine State AGfiled 2022-05-23(22d gap)Verified
- bd_1a59883a0195e6ffMaine State AGfiled 2022-08-22(69d gap)Verified
- bd_464f9d9da319c021California State AGfiled 2022-08-22(69d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554280
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 14, 2022
- Raw hash
- 0d40aeb3bc2f2670cab62c5625eb432432988c41448683a23d89f4235643c3d2
Reporting entity
- Name
- Comstar Technologies, LLCnorm: comstar technologies
Victim entity
- Name
- Comstar Technologies, LLCnorm: comstar technologies
Incident
- Discovered
- Mar 26, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- reporting to regulatory officials
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(80 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.