MalwareRansomwareData EncryptedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Cocoon, Inc.
bd_aef023f4861cfd9b · schema v1 · pii pii-v1
Full breach record for Cocoon, Inc. →Cocoon Inc. notified the New Hampshire Attorney General of a ransomware incident involving a network vendor. Unauthorized access occurred March 3-7, 2024, encrypting systems. Cocoon identified 25 NH residents' personal information (names, government IDs) was accessed. Notifications were mailed starting April 11, 2024, offering credit monitoring. Cocoon engaged cybersecurity professionals and enhanced security protocols.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8de020024d6a87a8Maine State AGfiled 2024-04-16Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cocoon-20240416.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 16, 2024
- Raw hash
- 380afa4cec5c70e92fac5cc03fa23e56543b1d4070a78b6b7609ee18dc2af219
Reporting entity
- Name
- Cocoon, Inc.norm: cocoon
- Domain
- cocoon-inc.com
Victim entity
- Name
- Cocoon, Inc.norm: cocoon
- Domain
- cocoon-inc.com
Incident
- Discovered
- Mar 27, 2024
- Materiality determined
- —
- Notification sent
- Apr 11, 2024
- Affected individuals
- 25
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- supply_chain
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.