HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumContained
CF ASTORIA HOLDING COMPANY, LLC
bd_fb533866bf26298f · schema v1 · pii pii-v1
Full breach record for CF ASTORIA HOLDING COMPANY, LLC →Astoria Company LLC, a lead exchange connecting consumers with financial services, disclosed a cyber-attack in late January 2021. A security researcher gained unauthorized access to a database containing personal information. Astoria discovered the intrusion on February 8, 2021, secured systems, and conducted a forensic investigation. The incident involved the exfiltration of names, addresses, SSNs, driver's license numbers, and employment data. Astoria reported the incident to the FBI and implemented additional security measures.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_e4ef8013ec5a9509Montana State AGfiled 2021-11-24Verified
- bd_07a6801ea9ddb03dMaine State AGfiled 2021-11-22(2d gap)Candidate
- bd_34ce05db71f3c0c1Hawaii State AGfiled 2021-11-22(2d gap)Verified
- bd_37660a0f6b826f53South Carolina State AGfiled 2021-11-22(2d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 2d gap
- bd_7d64fcc1510bb162California State AGfiled 2021-11-22(2d gap)Verified
- bd_83b289808d258c9eWashington State AGfiled 2021-11-22(2d gap)Verified
- bd_c3b4b7bbb5ac98beOregon State AGfiled 2021-11-22(2d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/12/Astoria-Notice-Letter-General.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 24, 2021
- Raw hash
- ab34d5245a58b57cbda1d9f6560c26ec42e3f84dea17b973092172f5abb3e45d
Reporting entity
- Name
- CF ASTORIA HOLDING COMPANY, LLCnorm: cf astoria
- Domain
- astoriacompany.com
Victim entity
- Name
- CF ASTORIA HOLDING COMPANY, LLCnorm: cf astoria
- Domain
- astoriacompany.com
Incident
- Discovered
- Feb 8, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- reported to the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 41 weeks(289 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.