HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Nashbar Direct, Inc.
bd_fa19758be55bd21d · schema v1 · pii pii-v1
Full breach record for Nashbar Direct, Inc. →Nashbar Direct, Inc. notified the New Hampshire Attorney General of a data breach affecting 1,307 state residents. Unauthorized access to previous website servers occurred starting in December 2008 and was confirmed on May 18, 2009. The incident exposed customer names, addresses, emails, passwords, and credit/debit card information. Nashbar took the site offline, migrated to a new host, engaged forensic experts, and notified payment networks and federal law enforcement.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,307 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/nashbar-direct-20090706.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 6, 2009
- Raw hash
- c66897a48525611d9e681180ddae256517ff3063fb877c07744ca6eaf4dae71f
Reporting entity
- Name
- Nelson Mullins Riley & Scarborough LLPnorm: nelson mullins riley scarborough
Victim entity
- Name
- Nashbar Direct, Inc.norm: nashbar direct
Incident
- Discovered
- May 18, 2009
- Materiality determined
- —
- Notification sent
- Jul 6, 2009
- Affected individuals
- 1,307
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney GeneralReported incident to federal law enforcement authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.