PAX Labs, Inc.
bd_8bd1ff1a24c029ad · schema v1 · pii pii-v1
Full breach record for PAX Labs, Inc. →PAX Labs, Inc. notified the New Hampshire Attorney General of a security incident where an unauthorized party gained access to a cloud-based website server between June 25 and July 22, 2016. The attacker installed unauthorized software to access payment card data (names, card numbers, CVV) of approximately 24 New Hampshire residents. PAX engaged forensic investigators, notified processors and law enforcement, and implemented enhanced firewall and monitoring rules. Affected residents were offered 12 months of credit monitoring and identity theft insurance.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 25, 2016
Begins
Jul 15, 2016
Discovered
Aug 11, 2016
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_a1430bc57e4c62122016-08-11Verified
- California State AGbd_ae35c365847dec6d2016-08-12 · +1dVerified
- Montana State AGbd_cdfab40ab9f0cea12016-08-12 · +1dCandidate
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.