HackingStolen CredentialsCustomer Data InvolvedBusiness Associate (HIPAA)IDENTITY_GOVERNMENTIDENTITY_BASICMediumActive
Kannact
bd_94cb9ce753b55184 · schema v1 · pii pii-v1
Full breach record for Kannact →Kannact, Inc., a healthcare wellness solution consultant, notified the NH AG of a data security incident discovered on March 13, 2023. An unauthorized user gained access to its network. Potentially exposed data includes Social Security numbers and driver's license numbers. The investigation was ongoing at the time of filing. Kannact engaged forensic investigators, disabled third-party file transfer access, and is offering credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_2f2008bf8d79c8e9Maine State AGfiled 2023-04-12(6d gap)Candidate
- bd_757c641c14a39099Oregon State AGfiled 2023-04-12(6d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/kannact-20230418.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 18, 2023
- Raw hash
- 78a3de6fd5497fb97c1150e1a74c136f9ed49782357ecd9706244fef2571dc78
Reporting entity
- Name
- Kannactnorm: kannact
- Domain
- kannact.com
Victim entity
- Name
- Kannactnorm: kannact
- Domain
- kannact.com
Incident
- Discovered
- Mar 13, 2023
- Materiality determined
- —
- Notification sent
- Apr 12, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed preliminary notification with New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.