HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Tutor Doctor
bd_8558f25b4f059f2a · schema v1 · pii pii-v1
Full breach record for Tutor Doctor →Tutor Doctor notified the New Hampshire Attorney General of a security incident affecting approximately 23 NH residents. An unauthorized third party gained remote access to a file share system storing client, tutor, and franchisee files between July 30 and August 2, 2023. Affected data likely included names and government IDs. Tutor Doctor engaged outside cybersecurity and legal counsel, implemented MFA, and initiated key rotation.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_03cef1d82950cda9Montana State AGfiled 2023-09-18(4d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/tutor-doctor-20230922.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2023
- Raw hash
- 1b9ff32922a9ef6496fdb1a1e0d41a14a4f4ee9197075c8931d0dd659fb7e3ff
Reporting entity
- Name
- Tutor Doctornorm: tutor doctor
Victim entity
- Name
- Tutor Doctornorm: tutor doctor
Incident
- Discovered
- Aug 2, 2023
- Materiality determined
- —
- Notification sent
- Sep 18, 2023
- Affected individuals
- 23
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.