HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowActive
CMT Industrial Solutions
bd_ca5dc2690f03340e · schema v1 · pii pii-v1
Full breach record for CMT Industrial Solutions →CMT Industrial Solutions, LLC voluntarily notified the New Hampshire Attorney General of a third-party data breach involving SignatureIT Ltd., an e-commerce platform provider. On November 16, 2023, SignatureIT detected unauthorized access to its Confluence collaboration platform, potentially exposing customer personal information. CMT notified approximately one Maryland resident and relevant regulators, including the FBI and CISA, on December 6, 2023. CMT's own systems were not directly accessed.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cmt-industrial-solutions-20231214.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 14, 2023
- Raw hash
- eb5613fac6c54ad78258065391b96c86b4807c1883b4ef565a5d11e4a13deaaa
Reporting entity
- Name
- CMT Industrial Solutionsnorm: cmt industrial
- Domain
- cmtindustrial.com
Victim entity
- Name
- CMT Industrial Solutionsnorm: cmt industrial
- Domain
- cmtindustrial.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Dec 6, 2023
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified the U.S. Federal Bureau of InvestigationNotified the Cybersecurity and Infrastructure Security Agency under the Cyber Incident Reporting for Critical Infrastructure ActNotified applicable U.S. state agenciesNotified the E.U. under the General Data Protection RegulationNotified the nationwide consumer reporting agencies
- Third party
- via SignatureIT Ltd.
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.