MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedSupply Chain (3P Vendor)Delayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
Certified Dispensary
bd_ff1b1fe5ef8024ba · schema v1 · pii pii-v1
Full breach record for Certified Dispensary →Certified Title Corporation notified 10,624 individuals (70 in NH) of a July 16, 2022 ransomware attack on third-party provider Cloudstar. The breach resulted in data exfiltration, exposing names, SSNs, and financial data. Certified Title discovered the leak on Jan 26, 2022, and sent notifications on March 23, 2022, offering credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_c1b65527cb514ef6Montana State AGfiled 2022-03-22(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/certified-title-20220323.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 23, 2022
- Raw hash
- 4b0d345cf74056e721e9cab72b08b73f573df02e4286984b20a27846d7de2ac6
Reporting entity
- Name
- Certified Dispensarynorm: certified dispensary
- Domain
- certifieddispensary.com
Victim entity
- Name
- Certified Dispensarynorm: certified dispensary
- Domain
- certifieddispensary.com
Incident
- Discovered
- Jan 26, 2022
- Materiality determined
- —
- Notification sent
- Mar 23, 2022
- Affected individuals
- 10,624
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via Cloudstar
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.