ACTIVEOutdoors
bd_c13c6eb011bc7653 · schema v1 · pii pii-v1
Full breach record for ACTIVEOutdoors →ACTIVEOutdoors, provider of online state hunting and fishing license applications, notified New Hampshire AG on September 19, 2016, of unauthorized access to its Affected Applications discovered on August 22, 2016. The incident potentially exposed personal information of 1,282 New Hampshire residents, including names, addresses, DOBs, and driver's license numbers, with 304 residents having full SSNs exposed. The threat was isolated to accounts created prior to July 2006/2007. ACTIVEOutdoors engaged a cybersecurity firm, secured the applications, and provided 24 months of identity repair and credit monitoring services to affected individuals.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_0043817ab2e52546California State AGfiled 2016-09-19Verified
- bd_006cc551e8755418Oregon State AGfiled 2016-09-19Candidate
- bd_64c2e5eba05780baMontana State AGfiled 2016-09-19Verified
- bd_ecb93ee8934ad17aWashington State AGfiled 2016-09-19Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/activeoutdoors-20160919.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 19, 2016
- Raw hash
- 94bc3adfd32d39782a1aae12421ab0c5bb0dcbab5226a4287d497a96b133b7ec
Reporting entity
- Name
- ACTIVEOutdoorsnorm: activeoutdoors
Victim entity
- Name
- ACTIVEOutdoorsnorm: activeoutdoors
Incident
- Discovered
- Aug 22, 2016
- Materiality determined
- —
- Notification sent
- Sep 19, 2016
- Affected individuals
- 1,282
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified Attorney General of the State of New HampshireWorking with impacted states and law enforcement in their own further investigations
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.