HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Myron Corp.
bd_9fc99454da68a8c9 · schema v1 · pii pii-v1
Full breach record for Myron Corp. →Myron Corp. d/b/a Pen Factory notified the New Hampshire Attorney General of a data security incident affecting 70 NH residents. Malicious code was placed on penfactory.com between September 2019 and April 15, 2020, capturing checkout data (names, emails, addresses, credit/debit card info). The code was removed on April 15, 2020, and notifications were sent on June 5, 2020. No SSNs were impacted. Remediation included platform upgrades and antivirus deployment.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5f68a92ee8ca1c89California State AGfiled 2020-06-05Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/myron-dba-pen-factory-20200605.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 5, 2020
- Raw hash
- ab2b8e5e27eb0aad9820bd960c0581b8d2cc6caf5fffdc017bee26da8c5f294e
Reporting entity
- Name
- Myron Corp.norm: myron
- Domain
- penfactory.com
Victim entity
- Name
- Myron Corp.norm: myron
- Domain
- penfactory.com
Incident
- Discovered
- Apr 15, 2020
- Materiality determined
- —
- Notification sent
- Jun 5, 2020
- Affected individuals
- 70
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.