HackingVulnerability ExploitSupply Chain (3P Vendor)TargetedIDENTITY_BASICIDENTITY_GOVERNMENTPIIMediumContained
BYTE FEDERAL, INC.
bd_bac8660828954ab9 · schema v1 · pii pii-v1
Full breach record for BYTE FEDERAL, INC. →Byte Federal disclosed a security breach on November 18, 2024, where a bad actor gained unauthorized access to a server by exploiting a vulnerability in third-party software. The company shut down its platform, isolated the actor, and secured the server. Customer PII, including government IDs and SSNs, was subject to unauthorized access, though no evidence of misuse was found. No user funds were compromised. Forensic investigation is ongoing.
Vermont clock⏱ VT AG >14 bday28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_49c9872bc3fd7264New Hampshire State AGfiled 2024-12-13(3d gap)Verified
- bd_daeb670bbf3e3f52Oregon State AGfiled 2024-12-13(3d gap)Verified
- bd_0db76d11ece12d45Montana State AGfiled 2024-12-11(5d gap)Candidate
- bd_43871576fda33170California State AGfiled 2024-12-11(5d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- bd_8379555c684c474bMaine State AGfiled 2024-12-11(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-12-16-byte-federal-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 16, 2024
- Raw hash
- 4a554ca1932c18a5288354c2ad4a1e7136a0d9c86634f08d5a3f60ed63908540
Reporting entity
- Name
- BYTE FEDERAL, INC.norm: byte federal
- Domain
- bytefederal.com
Victim entity
- Name
- BYTE FEDERAL, INC.norm: byte federal
- Domain
- bytefederal.com
Incident
- Discovered
- Nov 18, 2024
- Materiality determined
- —
- Notification sent
- Dec 16, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Cooperating with law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.