MisusePrivilege AbuseData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Three Rivers Community Action
bd_c3008c815c036e92 · schema v1 · pii pii-v1
Full breach record for Three Rivers Community Action →Tri-County Community Action Program (TCCAP) disclosed a data security incident on November 9, 2023, affecting clients in New Hampshire. A former employee copied confidential client data from TCCAP servers to a personal account on or about October 23, 2023. TCCAP engaged IT professionals and notified law enforcement, including the FBI. The breach involved PII and government identifiers. No specific count of affected individuals was provided.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/tri-county-community-action-program-aka-tccap-20231102.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 2, 2023
- Raw hash
- 56c3bb8080495ff418959e44cb43e015160f5662c352e1ba4bf21944bd84e4ac
Reporting entity
- Name
- Three Rivers Community Actionnorm: three rivers community action
Victim entity
- Name
- Three Rivers Community Actionnorm: three rivers community action
Incident
- Discovered
- Oct 23, 2023
- Materiality determined
- —
- Notification sent
- Nov 9, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- Internal
- Regulator citations
- notified law enforcement, including the Federal Bureau of Investigation
- Initial access
- insider_action
Compliance
- Time to disclose
- 10 days(10 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.