HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Newcourse Communications
bd_f54c33ae4852fef2 · schema v1 · pii pii-v1
Full breach record for Newcourse Communications →Newcourse Communications, Inc. disclosed a cybersecurity incident affecting its network between April 27 and May 3, 2022. The breach resulted in the unauthorized exfiltration of customer data, including names, loan account numbers, and partial Social Security numbers associated with mortgage statements. Newcourse notified HomeStreet Bank, which distributed breach notifications to affected individuals. The company engaged outside cybersecurity professionals for investigation and is reviewing internal security controls.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_a7499fed1b3917d3Montana State AGfiled 2022-09-09(1d gap)Verified
- bd_0f3785a2d73ab8cdWashington State AGfiled 2022-09-20(10d gap)Verified
- bd_ac7e3bc95043e097Oregon State AGfiled 2022-09-22(12d gap)Verified
- bd_22629816d6ed71feNew Hampshire State AGfiled 2022-08-25(16d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 70d gap
- bd_b985fda5696f937eMaine State AGfiled 2022-08-19(22d gap)Candidate
- bd_9f436faa7652dd3cMontana State AGfiled 2022-08-18(23d gap)Candidate
- bd_162ec875b80cff57Maine State AGfiled 2022-10-23(43d gap)Verified by operator
- bd_da8cccd6047f90caCalifornia State AGfiled 2022-10-28(48d gap)Verified by operator
- bd_84fe1f7d14f65eaaMaine State AGfiled 2022-10-29(49d gap)Verified by operator
- bd_3407f702f28d99cfMaine State AGfiled 2022-11-19(70d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-557117
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 10, 2022
- Raw hash
- b7c071222d83e7fc6054da04a3172e3d26d3c6365da0545dde2f1b27b9a16c70
Reporting entity
- Name
- Newcourse Communicationsnorm: newcourse communications
- Domain
- newcoursecc.com
Victim entity
- Name
- Newcourse Communicationsnorm: newcourse communications
- Domain
- newcoursecc.com
Incident
- Discovered
- May 3, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(130 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.