HackingCustomer Data InvolvedIDENTITY_BASICLowContained
Ora, LLC
bd_e3392b73212b4a76 · schema v1 · pii pii-v1
Full breach record for Ora, LLC →Ora, LLC notified the New Hampshire Attorney General on October 17, 2024, of a data security incident discovered on May 10, 2024. Unknown actors claimed to have downloaded data from Ora's network. Ora investigated with independent experts and confirmed on August 26, 2024, that personal information (names) of approximately 3 New Hampshire residents was included in the purportedly downloaded files. No evidence confirmed the data was actually taken. Ora offered complimentary identity monitoring via Kroll and implemented additional security features.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ora-20241017.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 17, 2024
- Raw hash
- 552d7f14f94f1c3863a1f516ca00aba352fde394af4db3502dabdafa004a10fa
Reporting entity
- Name
- Ora, LLCnorm: ora
Victim entity
- Name
- Ora, LLCnorm: ora
Incident
- Discovered
- May 10, 2024
- Materiality determined
- Aug 26, 2024
- Notification sent
- Oct 17, 2024
- Affected individuals
- 3
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
Compliance
- Time to disclose
- 23 weeks(160 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.