HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
City-Furniture
bd_c40105a03b952860 · schema v1 · pii pii-v1
Full breach record for City-Furniture →City Furniture, Inc. notified the New Hampshire Attorney General of a cybersecurity incident involving unauthorized access to its network between November 14, 2021, and June 12, 2022. The breach affected the personal information, including names and Social Security numbers, of two New Hampshire residents. City Furniture discovered the suspicious activity on June 12, 2022, engaged third-party forensic investigators, and notified law enforcement. Notifications were mailed to affected individuals on September 13, 2022, offering credit monitoring services.
Leak gap clock⏱ Leak >30d13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by hive about this victim predates this filing by 60 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_470914cee51c965bLeak Sitehivefiled 2022-07-14(60d gap)Candidate
Regulatory filings (1) · sorted by filing gap
- bd_d20051c6240c0cdaMaine State AGfiled 2022-09-13Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/city-furniture-20220913.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 13, 2022
- Raw hash
- bfc8a7df21847e244d3da7c149c7094c122c6fdaf8e67521e60a09d13bf65f17
Reporting entity
- Name
- City-Furniturenorm: city furniture
Victim entity
- Name
- City-Furniturenorm: city furniture
Incident
- Discovered
- Jun 12, 2022
- Materiality determined
- —
- Notification sent
- Sep 13, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 weeks(93 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.