HackingPhishingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedMulti-Stage ChainPIILowContained
Butler Brothers Supply Division
bd_d236eb6f2a18ce7e · schema v1 · pii pii-v1
Full breach record for Butler Brothers Supply Division →Butler Brothers Supply Division, LLC voluntarily notified the NH AG of a third-party data breach involving SignatureIT Ltd., an e-commerce platform provider. SignatureIT detected unusual activity on November 16, 2023, likely via spearphishing leading to unauthorized access. Approximately 157 Maryland residents may have had PII compromised. Butler Brothers notified users, regulators (FBI, CISA, EU), and consumer reporting agencies. Butler's own systems were not accessed.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8cba134bdf9b4d39Vermont State AGfiled 2023-12-06(8d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/butler-brothers-supply-division-20231214.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 14, 2023
- Raw hash
- 567d7aef6fcdea958dccfb7f65262c16706b945ea19794fb112a1441d164f4ff
Reporting entity
- Name
- Butler Brothers Supply Divisionnorm: butler brothers supply division
- Domain
- butlerbros.com
Victim entity
- Name
- Butler Brothers Supply Divisionnorm: butler brothers supply division
- Domain
- butlerbros.com
Incident
- Discovered
- Nov 16, 2023
- Materiality determined
- —
- Notification sent
- Dec 6, 2023
- Affected individuals
- 157
- Data types
- PII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified the U.S. Federal Bureau of InvestigationNotified the Cybersecurity and Infrastructure Security Agency under the Cyber Incident Reporting for Critical Infrastructure ActNotified applicable U.S. state agenciesNotified the E.U. under the General Data Protection Regulation
- Third party
- via SignatureIT Ltd.
- Initial access
- phishing_link
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.