HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICLowContained
Holden International
bd_c3b592981047a6d0 · schema v1 · pii pii-v1
Full breach record for Holden International →Holden International notified the New Hampshire Attorney General of a cybersecurity incident where an unauthorized actor accessed the company's email system between April and August 2021. The breach compromised the name, financial account number, and medical information of one New Hampshire resident. The company engaged third-party investigators, implemented multi-factor authentication, and audited its systems.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/holden-international-20220315.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 15, 2022
- Raw hash
- 7317b7c0d23dd4f08ec11b54700252106a96998ae48f92436393c07965fec53f
Reporting entity
- Name
- Holden Internationalnorm: holden international
Victim entity
- Name
- Holden Internationalnorm: holden international
Incident
- Discovered
- Jun 24, 2021
- Materiality determined
- —
- Notification sent
- Mar 7, 2022
- Affected individuals
- 1
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email CollectionT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 38 weeks(264 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.