HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Windhaven Investment Management, Inc.
bd_dd269faa8a2bf9b6 · schema v1 · pii pii-v1
Full breach record for Windhaven Investment Management, Inc. →Windhaven Investment Management, Inc. disclosed an unauthorized intrusion on a web server maintained by a third-party vendor. The incident was discovered in August 2013. The intruder may have accessed a database containing customer names, account numbers, custodians, and investment positions. Social Security numbers and dates of birth were not included. Windhaven disconnected the server, reported to law enforcement, and offered credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_90b4079b492caea4New Hampshire State AGfiled 2013-09-19(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-42740
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 23, 2013
- Raw hash
- 9903e620ef4e5ff3ff4f3bbb71807c4cb3716e7af391ef29397543ca5592ed95
Reporting entity
- Name
- Windhaven Investment Management, Inc.norm: windhaven investment management
Victim entity
- Name
- Windhaven Investment Management, Inc.norm: windhaven investment management
Incident
- Discovered
- Aug 1, 2013
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Third party
- via third-party vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.