NYDIG
bd_ccedfcccccadc649 · schema v1 · pii pii-v1
Full breach record for NYDIG →NYDIG Execution LLC and NYDIG Trust Company LLC reported a data security incident involving third-party vendor LogicGate, Inc. An unauthorized third party accessed and decrypted a backup file in LogicGate's Risk Cloud environment on February 23, 2021. The backup contained customer information including names, SSNs, bank account numbers, and passport/driver's license numbers. Approximately 551 individuals were affected, including 1 New Hampshire resident. NYDIG notified the NH Attorney General on April 26, 2021, and began notifying affected individuals on April 9, 2021. NYDIG is offering 24 months of credit monitoring.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/nydig-execution-nydig-trust-20210430.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 30, 2021
- Raw hash
- 8d5cbd6c89664a7b2bf625357adb2cf164d8584c2da727513dccce706bbfe2af
Reporting entity
- Name
- Debevoise & Plimpton LLPnorm: debevoise plimpton
Victim entity
- Name
- NYDIGnorm: nydig
- Domain
- nydig.com
Incident
- Discovered
- Apr 7, 2021
- Materiality determined
- —
- Notification sent
- Apr 27, 2021
- Affected individuals
- 551
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General pursuant to N.H. Rev. Stat. Ann. § 359-C:20
- Third party
- via LogicGate, Inc.
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.