HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedPIIEMPLOYMENTLowContained
Paycor
bd_b56d6786366e1533 · schema v1 · pii pii-v1
Full breach record for Paycor →Golf & Ski Warehouse, Inc. reported a breach affecting its third-party payroll vendor, Paycor. Paycor's MOVEit file transfer server was compromised, potentially exposing current and former employee information. GSW notified 55 New Hampshire residents on January 11, 2024, and offered credit monitoring services.
Leak gap clock✗ Leak >180d6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by dispossessor about this victim predates this filing by 413 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_fdc0123fb25a37f9Vermont State AGfiled 2024-01-24(13d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/golf-ski-warehouse-paycor-20240111.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 11, 2024
- Raw hash
- 2d37b11a920e504ce29d7b3c60993fca3d20d35859133317a3c5ee8c736ab237
Reporting entity
- Name
- Golf & Ski Warehouse, Inc.norm: golf ski warehouse
Victim entity
- Name
- Paycornorm: paycor
- Domain
- paycor.com
Incident
- Discovered
- Dec 1, 2023
- Materiality determined
- —
- Notification sent
- Jan 11, 2024
- Affected individuals
- 55
- Data types
- PIIEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified Attorney General John M. Formella, Office of the Attorney General, Consumer Protection & Antitrust Bureau
- Third party
- via Paycor
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.