HackingPhishingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICLowContained
Berkshire Production Supply, LLC
bd_c7084a15586a1315 · schema v1 · pii pii-v1
Full breach record for Berkshire Production Supply, LLC →Berkshire Production Supply (dba PTSolutions) reported a third-party vendor breach involving SignatureIT Ltd. On Nov 16, 2023, SignatureIT detected unusual activity via suspicious email leading to unauthorized access of its e-commerce platform. Approx 38 NH residents' PII was compromised. Berkshire notified FBI, CISA, state agencies, and EU regulators, and sent notices to affected users on Dec 6, 2023.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_1edf26fde3158507Maine State AGfiled 2023-12-15(1d gap)Verified
- bd_35b1102b074f177aWashington State AGfiled 2023-12-15(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/berkshire-production-supply-dba-ptsolutions-20231214.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 14, 2023
- Raw hash
- 6a39f942e793befbb6bd64725faf7d20c0ed464a1a48580d2f5648a8f9b47e2a
Reporting entity
- Name
- Berkshire Production Supply, LLCnorm: berkshire production supply
Victim entity
- Name
- Berkshire Production Supply, LLCnorm: berkshire production supply
Incident
- Discovered
- Nov 16, 2023
- Materiality determined
- —
- Notification sent
- Dec 6, 2023
- Affected individuals
- 38
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified the U.S. Federal Bureau of InvestigationNotified the Cybersecurity and Infrastructure Security Agency under the Cyber Incident Reporting for Critical Infrastructure ActNotified applicable U.S. state agenciesNotified the E.U. under the General Data Protection Regulation
- Third party
- via SignatureIT Ltd.
- Initial access
- phishing_link
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.