Comstar Technologies, LLC
bd_d818ee99f86b12dd · schema v1 · pii pii-v1
Full breach record for Comstar Technologies, LLC →Comstar LLC, a technology services provider, disclosed a data security event occurring between March 19 and 26, 2022. The company discovered suspicious activity on its servers, leading to unauthorized access to files containing customer personal information. Potentially affected data includes names, dates of birth, Social Security numbers, health insurance information, and medical assessments. Comstar engaged third-party forensic experts, secured its network, and is offering credit monitoring services to affected individuals. The breach impacts residents across multiple US states, with specific notifications sent to California, New York, and others.
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_b95db5904d98be34Maine State AGfiled 2022-06-30Verified
- bd_85177613717390c1California State AGfiled 2022-06-14(16d gap)Verified
- bd_7c3a134ab345e736HHS OCRfiled 2022-05-26(35d gap)Verified
- bd_7e62f29ad917b45dMontana State AGfiled 2022-05-25(36d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 53d gap
- bd_2302ead0876e2449Maine State AGfiled 2022-05-23(38d gap)Verified
- bd_1a59883a0195e6ffMaine State AGfiled 2022-08-22(53d gap)Verified
- bd_464f9d9da319c021California State AGfiled 2022-08-22(53d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554800
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2022
- Raw hash
- f6d4e14baab68ac812f7be81b0a6490330694f30dc8e2c822387fe04b6d5b80e
Reporting entity
- Name
- Comstar Technologies, LLCnorm: comstar technologies
Victim entity
- Name
- Comstar Technologies, LLCnorm: comstar technologies
Incident
- Discovered
- Mar 26, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- reporting to regulatory officials
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(96 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.