HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Newcourse Communications
bd_da8cccd6047f90ca · schema v1 · pii pii-v1
Full breach record for Newcourse Communications →Newcourse Communications, Inc. disclosed a security incident occurring between April 27, 2022, and May 3, 2022, where unauthorized access resulted in the exfiltration of customer data including names, addresses, loan numbers, and the last four digits of Social Security Numbers. The breach affected customers of First United Bank. Newcourse engaged outside cybersecurity professionals, offered 24 months of credit monitoring and identity theft protection through IDX, and established a toll-free response line. No identity fraud was reported at the time of notification.
California clockDiscovered Oct 18, 2022 → Notified Oct 18, 20220d ✓ CA 60-day OK10 days discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_84fe1f7d14f65eaaMaine State AGfiled 2022-10-29(1d gap)Verified by operator
- bd_162ec875b80cff57Maine State AGfiled 2022-10-23(5d gap)Verified by operator
- bd_3407f702f28d99cfMaine State AGfiled 2022-11-19(22d gap)Verified by operator
- bd_ac7e3bc95043e097Oregon State AGfiled 2022-09-22(36d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 71d gap
- bd_0f3785a2d73ab8cdWashington State AGfiled 2022-09-20(38d gap)Verified
- bd_f54c33ae4852fef2California State AGfiled 2022-09-10(48d gap)Verified
- bd_a7499fed1b3917d3Montana State AGfiled 2022-09-09(49d gap)Verified
- bd_b985fda5696f937eMaine State AGfiled 2022-08-19(70d gap)Candidate
- bd_9f436faa7652dd3cMontana State AGfiled 2022-08-18(71d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-558699
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 28, 2022
- Raw hash
- 07605247b4bf1663c96e29d902e213a79276c5060b3d401e667b46c935ce58ac
Reporting entity
- Name
- Newcourse Communicationsnorm: newcourse communications
Victim entity
- Name
- Newcourse Communicationsnorm: newcourse communications
Incident
- Discovered
- Oct 18, 2022
- Materiality determined
- —
- Notification sent
- Oct 18, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 days(10 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 18, 2022→ Notified: Oct 18, 20220d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.