HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICLowContained
Yesway
bd_ad4e168bdab03521 · schema v1 · pii pii-v1
Full breach record for Yesway →Yesway notified the NH AG of a third-party breach involving Paycor's MOVEit file transfer program. An unauthorized person exploited a vulnerability to access files containing PII of one NH resident. Yesway mailed notification on Jan 24, 2024, and offered two years of identity theft protection.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_41bbac558d38a784Indiana State AGfiled 2024-01-24Candidate
- bd_4a1b99e0197cad10Maine State AGfiled 2024-01-24Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/yesway-20240124.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 24, 2024
- Raw hash
- bc48930dfad82d0ee1e6853047400d88fd741fafa591c67eb696a95535ad79c7
Reporting entity
- Name
- Yeswaynorm: yesway
Victim entity
- Name
- Yeswaynorm: yesway
Incident
- Discovered
- Nov 30, 2023
- Materiality determined
- —
- Notification sent
- Jan 24, 2024
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Third party
- via Paycor
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.