HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Overseas Shipholding Group, Inc.
bd_f56f78da8d95bfa4 · schema v1 · pii pii-v1
Full breach record for Overseas Shipholding Group, Inc. →Overseas Shipholding Group, Inc. notified the New Hampshire Attorney General of a security incident where an unauthorized actor accessed and took files containing personal information of 92 New Hampshire residents on August 5, 2024. OSG secured systems, investigated, and sent notifications on December 2, 2024, offering one year of credit monitoring.
Leak gap clock⏱ Leak >90d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 4 about the same incident.View merged incident
A leak claim by ransomhub about this victim predates this filing by 104 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_0e1d268849e71eefMaine State AGfiled 2024-12-02Candidate
- bd_4572f9d6af857adaVermont State AGfiled 2024-12-02Verified
- bd_700f147321d34c86California State AGfiled 2024-12-02Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/overseas-shipholding-group-20241202.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 2, 2024
- Raw hash
- 0abc79c8e5d9903fa800d5b27deae34b8b439310dbc529f978b85d5c6ba291ec
Reporting entity
- Name
- Overseas Shipholding Group, Inc.norm: overseas shipholding
- Domain
- osg.com
Victim entity
- Name
- Overseas Shipholding Group, Inc.norm: overseas shipholding
- Domain
- osg.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Dec 2, 2024
- Affected individuals
- 92
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- valid_credentials
Compliance
- Compliance flags
- Leak >90d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.