HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedPCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
PAX Labs, Inc.
bd_8bd1ff1a24c029ad · schema v1 · pii pii-v1
Full breach record for PAX Labs, Inc. →PAX Labs, Inc. notified the New Hampshire Attorney General of a security incident where an unauthorized party gained access to a cloud-based website server between June 25 and July 22, 2016. The attacker installed unauthorized software to access payment card data (names, card numbers, CVV) of approximately 24 New Hampshire residents. PAX engaged forensic investigators, notified processors and law enforcement, and implemented enhanced firewall and monitoring rules. Affected residents were offered 12 months of credit monitoring and identity theft insurance.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_ae35c365847dec6dCalifornia State AGfiled 2016-08-12(1d gap)Verified
- bd_cdfab40ab9f0cea1Montana State AGfiled 2016-08-12(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pax-labs-20160811.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 11, 2016
- Raw hash
- 8c9030ad38311fcffaa7712a0cf283b23875cee7f5217ef0609016c21ca4220b
Reporting entity
- Name
- PAX Labs, Inc.norm: pax labs
Victim entity
- Name
- PAX Labs, Inc.norm: pax labs
Incident
- Discovered
- Jul 15, 2016
- Materiality determined
- —
- Notification sent
- Aug 12, 2016
- Affected individuals
- 24
- Data types
- PCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- informed federal law enforcement authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.