HackingData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Terrier Media Buyer, Inc.
bd_f42409412491ca28 · schema v1 · pii pii-v1
Full breach record for Terrier Media Buyer, Inc. →Terrier Media Buyer, Inc. dba Cox Media Group notified the NH AG of a June 3, 2021 incident where a threat actor gained unauthorized remote access to HR systems. Approximately 21 NH residents were at risk. Data at risk included names, SSNs, driver's licenses, and financial account numbers. No evidence confirmed data was exfiltrated. CMG engaged forensic experts, notified the FBI, and offered 24 months of credit monitoring via Experian.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_29839e00494e2ecbWashington State AGfiled 2021-10-28(10d gap)Candidate
- bd_7a462900aa4679d7California State AGfiled 2021-10-08(10d gap)Verified
- bd_03ea52157fe9b061California State AGfiled 2021-11-02(15d gap)Verified
- bd_9cae2e363ad0316dMaine State AGfiled 2021-11-02(15d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/terrier-media-buyer-dba-cox-media-20211018.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 18, 2021
- Raw hash
- fd40529fdd41d21cc7a17f26f3eccb54f3e69909512f9e4b8e6f490e5962f2b6
Reporting entity
- Name
- Terrier Media Buyer, Inc.norm: terrier media buyer
Victim entity
- Name
- Terrier Media Buyer, Inc.norm: terrier media buyer
Incident
- Discovered
- Jun 3, 2021
- Materiality determined
- —
- Notification sent
- Oct 8, 2021
- Affected individuals
- 21
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported the incident to the FBI, including the Newark and Dallas field officesnotifying your office as well as individuals whose personal information was at risk
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 weeks(137 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.