CENTRAL SECURITIES CORPORATION
bd_da8e4d2e5088976a · schema v1 · pii pii-v1
Full breach record for CENTRAL SECURITIES CORPORATION →Central Securities Corporation, a closed-end investment management company, notified the New Hampshire Attorney General of a cybersecurity incident. An unauthorized third party accessed internal systems on or about April 17, 2024, via a legitimate account of a third-party vendor. The actor exfiltrated data containing names and other personal information of seven New Hampshire residents on or about May 20, 2024. Central Securities discovered the activity on May 20, 2024, engaged forensic experts, notified law enforcement, terminated the vendor's access, and began mailing notifications on September 30, 2024, offering credit monitoring services.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3e34accc2e6a85e7Maine State AGfiled 2024-09-30Candidate
- bd_9dfb83fe07bfdcacIndiana State AGfiled 2024-09-30Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/central-securities-20240930.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 30, 2024
- Raw hash
- e869eb00d0f79342f2e1f1c9b76b17fdada349330e46487ebbda705dc75a86db
Reporting entity
- Name
- CENTRAL SECURITIES CORPORATIONnorm: central securities
- Domain
- centralsecurities.com
Victim entity
- Name
- CENTRAL SECURITIES CORPORATIONnorm: central securities
- Domain
- centralsecurities.com
Incident
- Discovered
- May 20, 2024
- Materiality determined
- —
- Notification sent
- Sep 30, 2024
- Affected individuals
- 7
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Department of Justice
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 19 weeks(133 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.