HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
GoHenry
bd_c8211f50f181c7cb · schema v1 · pii pii-v1
Full breach record for GoHenry →GoHenry Inc. reported unauthorized access to customer profiles between September 19 and October 13, 2022. The incident involved the theft of personal information, including government IDs, for children's accounts. GoHenry confirmed the breach on April 3, 2023, and notified affected individuals in May 2023. 13 Rhode Island residents were affected.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_2144be1c9575322cMontana State AGfiled 2023-05-08Candidate
- bd_29dad984702e127aMaine State AGfiled 2023-05-08Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/gohenry-20230508.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 8, 2023
- Raw hash
- faed1e64f3510d4d9dfa143e5b036f839e0511cfff0dc4267f0095e19af6f55c
Reporting entity
- Name
- GoHenrynorm: gohenry
Victim entity
- Name
- GoHenrynorm: gohenry
Incident
- Discovered
- Oct 13, 2022
- Materiality determined
- Apr 3, 2023
- Notification sent
- May 8, 2023
- Affected individuals
- 13
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 30 weeks(207 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.