MalwareRansomwareRansom DemandedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Pizzuti
bd_8bea586f89008bad · schema v1 · pii pii-v1
Full breach record for Pizzuti →Pizzuti Companies notified the New Hampshire Attorney General of a ransomware incident occurring June 17-20, 2021. An unauthorized third party accessed systems, encrypted data, and exfiltrated one NH resident's name and SSN. Pizzuti paid a ransom, engaged forensic investigators, and notified the individual. Remediation included additional technical controls.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pizzuti-companies-20210824.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 24, 2021
- Raw hash
- a8f0bec5e0ed42eeb74348963889bcaa8885aee4c0968e8bc1491591b680c7e6
Reporting entity
- Name
- Pizzutinorm: pizzuti
- Domain
- pizzuti.com
Victim entity
- Name
- Pizzutinorm: pizzuti
- Domain
- pizzuti.com
Incident
- Discovered
- Jun 21, 2021
- Materiality determined
- —
- Notification sent
- Aug 24, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General pursuant to N.H. Rev. Stat. § 359-C:20
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.