DisclosureLens
HackingProfessional ServicesTechnologyProfessional ServicesVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedPIIIdentity (basic)Government IDMediumContained

TPA Technologies

bd_de3772d0f114952f · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 18, 2023

Filed

Jan 18, 2024

To disclose

4 weeks

Affected

5state residents only

Confidence

66%
Full breach record for TPA Technologies

TPA Technologies notified New Hampshire residents of a data breach involving its former payroll vendor, Paycor. Paycor was impacted by zero-day vulnerabilities in MOVEit Transfer disclosed by Progress Software in May/June 2023. TPA learned of the impact on December 18, 2023. The incident involved unauthorized access to employee payroll data. TPA terminated its relationship with Paycor and offered credit monitoring via Experian to affected individuals.

Incident timeline

undetected · 201 days
discovery → filing · 4 weeks / 31 days

May 31, 2023

Begins

Dec 18, 2023

Discovered

Jan 18, 2024

Filed

vs. sector median

13 wks faster

Part of Paycor supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed5 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.