AccidentalMisdeliveryCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICMediumResolved
ONESOURCE VIRTUAL, INC.
bd_ec9125f0c70f494d · schema v1 · pii pii-v1
Full breach record for ONESOURCE VIRTUAL, INC. →OneSource Virtual, Inc. notified the New Hampshire Attorney General of a data security incident where an employee inadvertently emailed a password-protected spreadsheet containing confidential benefits information (including SSNs and names) to two employees of a customer on August 1, 2021. OSV discovered the error on August 10, 2021. One New Hampshire resident was affected. Remediation included employee retraining and offering 12 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/onesource-virtual-20210927.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 27, 2021
- Raw hash
- 8d2c52676d76ffeebbcd6611d8128c995484cb8d3cfebe1d5e4394b0d8b365c2
Reporting entity
- Name
- ONESOURCE VIRTUAL, INC.norm: onesource virtual
Victim entity
- Name
- ONESOURCE VIRTUAL, INC.norm: onesource virtual
Incident
- Discovered
- Aug 10, 2021
- Materiality determined
- —
- Notification sent
- Sep 27, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- Internal
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.