BCD Travel USA LLC
bd_bde79341f9c04af6 · schema v1 · pii pii-v1
Full breach record for BCD Travel USA LLC →BCD Travel USA LLC notified the New Hampshire Attorney General of a cybersecurity incident involving the MOVEit Transfer application. The breach exploited a zero-day vulnerability (CVE-2023-34362) exploited by the CL0P ransomware group. Unauthorized access occurred on May 29, 2023, and was discovered by BCD on June 1, 2023. The incident resulted in the exfiltration of personal information belonging to 17 New Hampshire residents. BCD engaged forensic experts, took the application offline, and began notifying affected individuals on August 11, 2023, offering one year of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 29, 2023
Begins
Jun 1, 2023
Discovered
Aug 14, 2023
Filed
vs. sector median
8 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Indiana State AGbd_16211401bd447ec82023-08-11 · +3dVerified
- Massachusetts State AGbd_1d7f5bf7ecfac6882023-08-18 · +4dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Aug 11 (IN), last Aug 18 (MA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.