BCD Travel USA LLC notified the New Hampshire Attorney General of a cybersecurity incident involving the MOVEit Transfer application. The breach exploited a zero-day vulnerability (CVE-2023-34362) exploited by the CL0P ransomware group. Unauthorized access occurred on May 29, 2023, and was discovered by BCD on June 1, 2023. The incident resulted in the exfiltration of personal information belonging to 17 New Hampshire residents. BCD engaged forensic experts, took the application offline, and began notifying affected individuals on August 11, 2023, offering one year of credit monitoring.
Affected (this filing): 17