TwoBirch
bd_f3480485723803fd · schema v1 · pii pii-v1
Full breach record for TwoBirch →TwoBirch notified the NH AG of a cyber-attack compromising payment card data (name, address, card number, CVV) for 9 NH residents. Suspicious activity was discovered on Jan 8, 2021. The compromise occurred between Feb 18, 2020, and Jan 18, 2021. TwoBirch engaged forensic specialists, implemented additional security safeguards, and notified card brands and regulators.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 18, 2020
Begins
Jan 8, 2021
Discovered
Jun 1, 2021
Filed
vs. sector median
+13 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_38712bb9f309bf2b2021-05-26 · +6dVerified
- Indiana State AGbd_a3c58804539949112021-05-26 · +6dVerified
- Maine State AGbd_f3cbba6ac787a8052021-05-26 · +6dCandidate
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing May 26 (MA), last Jun 1 (NH) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.