HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CommuteAir •
bd_edea170223ff015b · schema v1 · pii pii-v1
Full breach record for CommuteAir • →CommuteAir, LLC. reported that on November 9, 2022, an unauthorized individual gained access to a third-party HRIS via an API. The incident involved employee names, dates of birth, and the last four digits of SSNs. CommuteAir engaged cybersecurity consultants, notified law enforcement, and offered one year of identity theft protection.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_92d58de45884371bMaine State AGfiled 2022-11-17(1d gap)Candidate
- bd_c09ec8830c2a9fe4Montana State AGfiled 2022-11-17(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/commuteair-20221118.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 18, 2022
- Raw hash
- 5e8cc79dd4a9ee6fac08a2105eba5d461f8cc6358fd320958c92f13881272dbf
Reporting entity
- Name
- CommuteAir •norm: commuteair
- Domain
- commuteair.com
Victim entity
- Name
- CommuteAir •norm: commuteair
- Domain
- commuteair.com
Incident
- Discovered
- Nov 9, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the appropriate authoritiesWorking closely with law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 days(9 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.