HackingStolen CredentialsEmployee Data InvolvedMulti-Stage ChainCREDENTIALSIDENTITY_BASICLowActive
OSIsoft, LLC
bd_d9f28ba801c8d7b4 · schema v1 · pii pii-v1
Full breach record for OSIsoft, LLC →OSIsoft, LLC notified the California AG of a credential theft incident affecting employees, interns, consultants, and contractors. Stolen credentials were used to remotely access OSIsoft computers between March 2017 and July 2018. The company is investigating with third-party providers and expediting MFA deployment. All OSI domain accounts are considered affected.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-141865
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 16, 2018
- Raw hash
- 591ccc3ab9842627f2f888303f0fd738cc4931d68e89003ae2cfda39433109c6
Reporting entity
- Name
- OSIsoft, LLCnorm: osisoft
Victim entity
- Name
- OSIsoft, LLCnorm: osisoft
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Nov 16, 2018
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.