BCD Travel USA LLC
bd_bde79341f9c04af6 · schema v1 · pii pii-v1
Full breach record for BCD Travel USA LLC →BCD Travel USA LLC notified the New Hampshire Attorney General of a cybersecurity incident involving the MOVEit Transfer application. The breach exploited a zero-day vulnerability (CVE-2023-34362) exploited by the CL0P ransomware group. Unauthorized access occurred on May 29, 2023, and was discovered by BCD on June 1, 2023. The incident resulted in the exfiltration of personal information belonging to 17 New Hampshire residents. BCD engaged forensic experts, took the application offline, and began notifying affected individuals on August 11, 2023, offering one year of credit monitoring.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/bcd-travel-usa-20230814.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 14, 2023
- Raw hash
- 0d8c803405154d319457dc600c5a363daed3ad3a5792140b3f61d1c13964a809
Reporting entity
- Name
- HOGAN LOVELLS US LLPnorm: hogan lovells us
Victim entity
- Name
- BCD Travel USA LLCnorm: bcd travel usa
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Aug 11, 2023
- Affected individuals
- 17
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access· CL0P Ransomware Gang
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- CL0P Ransomware GangExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.