CF ASTORIA HOLDING COMPANY, LLC
ent_019e5a1b988ce97e884bf549ac823dfa
Disclosures
9
State AG · 8 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
940,000
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CF ASTORIA HOLDING COMPANY, LLC
- Normalized
- cf astoria— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300YK18GP443KF418
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- 🦬Montana State AGas victim2021-11-24
Astoria Company LLC reported a data breach to the Montana Attorney General. The breach was reported on 2021-11-24. The breach occurred from 1/5/2021 to 2/8/2021. 1,543 Montana residents were affected.
- 💎Delaware State AGas victim2021-11-24
Astoria Company LLC, a lead exchange connecting consumers with financial services, disclosed a cyber-attack in late January 2021. A security researcher gained unauthorized access to a database containing personal information. Astoria discovered the intrusion on February 8, 2021, secured systems, and conducted a forensic investigation. The incident involved the exfiltration of names, addresses, SSNs, driver's license numbers, and employment data. Astoria reported the incident to the FBI and implemented additional security measures.
- 🦞Maine State AGas victim2021-11-22
Astoria Company LLC experienced an external system breach on January 19, 2021, which was discovered on February 8, 2021. The breach affected 995 Maine residents, compromising their names and driver's license or non-driver identification card numbers. Affected individuals were notified electronically on November 24, 2021.
- 🌺Hawaii State AGas victim2021-11-22
Astoria Company reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2021/11.22. Breach type: Hackers/Unauthorized Access. 3,290 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.
- 🌴South Carolina State AGas victim2021-11-22
Astoria Company LLC, a lead exchange connecting consumers with financial services, disclosed a cyber-attack in late January 2021. A security researcher gained unauthorized access to a system containing personal information. Astoria discovered the intrusion on Feb 8, 2021, secured systems, and reported the incident to the FBI. Affected data included names, addresses, SSNs, driver's license numbers, and employment information. The incident is reported to South Carolina regulators.
- 🐻California State AGas victim2021-11-22
Astoria Company LLC, a lead exchange operator, disclosed a cybersecurity incident in January 2021 where unauthorized actors accessed a system containing personal information. The breach affected individuals' names, addresses, SSNs, and driver's license numbers. Astoria reported the incident to the FBI, secured systems, and provided one year of free identity monitoring services to affected individuals across multiple states.
- 🌲Washington State AGas victim2021-11-22
Astoria Company LLC, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2021-02-08 and filed notice on 2021-11-22. 22,095 Washington residents were affected. 287 days elapsed between awareness and notification. 20 days to identify the breach. 0 days to contain the breach.
- 🦫Oregon State AGas victim2021-11-22
Astoria Company LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2021-11-22. The breach occurred during 1/19/2021 - 1/29/2021. The breach was discovered on 2/8/2021. 940,000 individuals were affected. Notice was sent on 11/24/2021.
- 💎Delaware State AGas victim2021-01-29
Astoria Company LLC, a lead exchange connecting consumers with financial services, notified individuals of a cyber-attack in late January 2021. A security researcher gained unauthorized access to a system containing personal information. Astoria discovered the intrusion on Feb 8, 2021, secured systems, and reported the incident to the FBI. Affected data included names, addresses, SSNs, driver's license numbers, and employment information. The notice was filed with the Delaware Attorney General.