HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Boston Capital Holdings LP
bd_cdd5e07e39628f06 · schema v1 · pii pii-v1
Full breach record for Boston Capital Holdings LP →Boston Capital Holdings LP notified the California AG of unauthorized access to its systems between Jan 16-22, 2026. The actor used legitimate cloud systems to circumvent security controls and accessed/copied files. Discovery occurred on Feb 12, 2026. Affected data includes names and potentially SSNs. The company engaged cybersecurity specialists, contained the incident, and is offering identity monitoring.
California clockDiscovered Feb 12, 2026 → Notified May 18, 202695d ✗ CA 30-day late14 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_0f1ccf31ebc47b7fNew Hampshire State AGfiled 2026-05-18Verified
- bd_22628c792696357dVermont State AGfiled 2026-05-18Verified
- bd_2e06c1f7553bb4caIndiana State AGfiled 2026-05-18Verified
- bd_7b5266914026165fMaine State AGfiled 2026-05-18Verified by operator
Show 3 more filings ↓Show fewer ↑up to 17d gap
- bd_966984c8bec10ad5Oregon State AGfiled 2026-05-18Verified by operator
- bd_2e07299b6adc2434Texas State AGfiled 2026-05-19(1d gap)Verified by operator
- bd_d48a16fe689f76b0Massachusetts State AGfiled 2026-05-01(17d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-623610
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 18, 2026
- Raw hash
- 4a9d08b30e972077185a345ed3c36ed31c201c1b3561728b3a0921538152b3e7
Reporting entity
- Name
- Boston Capital Holdings LPnorm: boston capital
- Domain
- bostoncapital.com
Victim entity
- Name
- Boston Capital Holdings LPnorm: boston capital
- Domain
- bostoncapital.com
Incident
- Discovered
- Feb 12, 2026
- Materiality determined
- —
- Notification sent
- May 18, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(95 days from discovery to filing)
- Compliance flags
- CA 30-day late · 95dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 12, 2026→ Notified: May 18, 202695d 30 calendar days CA 30-day late California Consumers notified: May 18, 2026→ AG copy submitted: May 18, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.