HackingVulnerability ExploitCustomer Data InvolvedPIICREDENTIALSLowContained
CUSO Financial Services, L.P.
bd_efcb6767e0e2d826 · schema v1 · pii pii-v1
Full breach record for CUSO Financial Services, L.P. →CUSO Financial Services, LP notified New Hampshire residents of a security event discovered on October 20, 2023, involving a vulnerability in Barracuda Networks email application. Unauthorized access to historical emails and attachments dating back to July 5, 2022, was possible. One New Hampshire resident was affected. CFS reported the incident to federal law enforcement and offered credit monitoring services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_5e7d3bbb2432fd7dIndiana State AGfiled 2024-02-16Verified
- bd_8322500873ed6ac4Montana State AGfiled 2024-02-16Candidate
- bd_9c6021565739f156Maine State AGfiled 2024-02-16Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cuso-financial-services-20240216.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 16, 2024
- Raw hash
- b799648a2c9a2d4ce3c6b896bc4b111a5a7d908c02b0ce35a3a5d9938ed57dcb
Reporting entity
- Name
- CUSO Financial Services, L.P.norm: cuso financial
Victim entity
- Name
- CUSO Financial Services, L.P.norm: cuso financial
Incident
- Discovered
- Oct 20, 2023
- Materiality determined
- —
- Notification sent
- Feb 16, 2024
- Affected individuals
- 1
- Data types
- PIICREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- reported to federal law enforcementproviding written notice of this event to appropriate state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(119 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.