MalwareIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Moss -
bd_d6c9341e30e07e2d · schema v1 · pii pii-v1
Full breach record for Moss - →Moss, Inc. notified the NH Attorney General of a ransomware incident discovered on September 20, 2020. The attack resulted in the exfiltration of one New Hampshire resident's name, SSN, address, and credit card number. Notifications were mailed on January 13, 2021. The company engaged forensic consultants and law enforcement (FBI) and implemented additional security safeguards.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/moss-20210119.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 19, 2021
- Raw hash
- fc54c2230e785919c34827ee9653e49674f1bb60211ccc08dc124a578d5bc373
Reporting entity
- Name
- Moss -norm: moss
- Domain
- moss.com
Victim entity
- Name
- Moss -norm: moss
- Domain
- moss.com
Incident
- Discovered
- Sep 20, 2020
- Materiality determined
- —
- Notification sent
- Jan 13, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
Compliance
- Time to disclose
- 17 weeks(121 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.