MalwareRansomwareData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Divvy
bd_9e19f2e914d204ec · schema v1 · pii pii-v1
Full breach record for Divvy →Divvy Up, Inc. notified the New Hampshire Attorney General of a cybersecurity incident involving its website hosting provider. Malware was downloaded to the hosted website, allowing an unknown third party to access payment transactions between May 10, 2021, and June 18, 2021. Affected data included customer names, addresses, and payment card details (number, CVC, expiration). 152 New Hampshire residents were affected. Divvy Up engaged a security service, upgraded protocols, and restricted payments to PayPal during remediation.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_5974d6aca33ca5d9California State AGfiled 2021-07-30(3d gap)Verified
- bd_e80e9f81608676a8Montana State AGfiled 2021-07-30(3d gap)Verified
- bd_c0c5e3cb53ac3092Maine State AGfiled 2021-05-04(90d gap)Verified
- bd_3e0b7231e130092bOregon State AGfiled 2021-05-03(91d gap)Candidate
Show 4 more filings ↓Show fewer ↑up to 91d gap
- bd_3fb2bd19bcf8bf84Montana State AGfiled 2021-05-03(91d gap)Verified
- bd_6a530a38e06eba6bCalifornia State AGfiled 2021-05-03(91d gap)Verified
- bd_8fc9f6edf9594d0bWashington State AGfiled 2021-05-03(91d gap)Verified
- bd_f2b3150d821352fbWashington State AGfiled 2021-05-03(91d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/american-anthropological-20210802.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 2, 2021
- Raw hash
- d153d74b852a89ab6a585259d610ab0e3d7dde09118fa453ce475ea54397b63a
Reporting entity
- Name
- Divvynorm: divvy
- Domain
- divvy.app
Victim entity
- Name
- Divvynorm: divvy
- Domain
- divvy.app
Incident
- Discovered
- Mar 10, 2021
- Materiality determined
- —
- Notification sent
- Jul 29, 2021
- Affected individuals
- 152
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notification has also been made to the three major credit reporting agencies
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 weeks(145 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.