HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
PFU America
bd_d9c6cd38af888e04 · schema v1 · pii pii-v1
Full breach record for PFU America →PFU America, Inc. notified the New Hampshire Attorney General of a data security incident involving the fujitsuscannerstore.com website. Unauthorized access occurred between November 30, 2020, and July 27, 2021, compromising payment card information (names, billing/shipping addresses, card numbers, CVVs) for 32 New Hampshire residents. PFU took the site offline, engaged forensic specialists, and offered 12 months of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_55c849d81dd270b0Maine State AGfiled 2021-09-17Candidate
- bd_8eeed4df36947012Montana State AGfiled 2021-09-17Verified by operator
- bd_c804fe250fecf56eCalifornia State AGfiled 2021-09-17Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pfu-america-20210917.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 17, 2021
- Raw hash
- fea4db3e6977578b2df12bf60386373cd25dc1762c5493aa5573db436d96c6ca
Reporting entity
- Name
- PFU Americanorm: pfu america
Victim entity
- Name
- PFU Americanorm: pfu america
Incident
- Discovered
- Jul 27, 2021
- Materiality determined
- —
- Notification sent
- Sep 17, 2021
- Affected individuals
- 32
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.