CENTRAL SECURITIES CORPORATION
bd_da8e4d2e5088976a · schema v1 · pii pii-v1
Full breach record for CENTRAL SECURITIES CORPORATION →Central Securities Corporation, a closed-end investment management company, notified the New Hampshire Attorney General of a cybersecurity incident. An unauthorized third party accessed internal systems on or about April 17, 2024, via a legitimate account of a third-party vendor. The actor exfiltrated data containing names and other personal information of seven New Hampshire residents on or about May 20, 2024. Central Securities discovered the activity on May 20, 2024, engaged forensic experts, notified law enforcement, terminated the vendor's access, and began mailing notifications on September 30, 2024, offering credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 17, 2024
Begins
May 20, 2024
Discovered
Sep 30, 2024
Filed
vs. sector median
+10 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteundergroundbd_d43ddf1ce3a7ba142024-05-15 · +138dVerified by operator
Regulatory filings (3) · sorted by filing gap
- Maine State AGbd_3e34accc2e6a85e72024-09-30Candidate
- Indiana State AGbd_9dfb83fe07bfdcac2024-09-30Verified
- Massachusetts State AGbd_a498a58822cddbf72024-09-30Verified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.