HackingVulnerability ExploitCustomer Data InvolvedTargetedFINANCIAL_ACCOUNTPIILowContained
SeneGence
bd_854ff878cb7e56d1 · schema v1 · pii pii-v1
Full breach record for SeneGence →SGII, Inc. dba SeneGence notified the NH AG of a data security incident affecting 4 NH residents. An unknown threat actor exploited a vulnerability in the Adobe Magento ecommerce platform on July 22, 2024, to inject malicious code and capture credit card information via a fraudulent checkout page. SeneGence detected the incident on July 25, 2024, and remediated it by July 27. Notices were mailed on November 22, 2024, offering credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_83cb0ce868f705c8Maine State AGfiled 2024-11-25Verified
- bd_00a9299bc286074aMontana State AGfiled 2024-11-22(3d gap)Verified
- bd_e0ee1c62b14763f2Indiana State AGfiled 2024-11-22(3d gap)Verified
- bd_5d7d1e68fcd35e6dVermont State AGfiled 2024-11-21(4d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sgii-senegence-20241125.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 25, 2024
- Raw hash
- faad786aecebebdf053f64d0e05047040b621d0405dac6ecf0e9b638e53ff839
Reporting entity
- Name
- SeneGencenorm: senegence
- Domain
- senegence.com
Victim entity
- Name
- SeneGencenorm: senegence
- Domain
- senegence.com
Incident
- Discovered
- Jul 25, 2024
- Materiality determined
- —
- Notification sent
- Nov 22, 2024
- Affected individuals
- 4
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 weeks(123 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.