The Maine Office of the Attorney General disclosed a ransomware attack targeting Cayan, LLC, which occurred between October 29, 2020, and November 18, 2020, and was reported on July 13, 2021. The incident compromised sensitive personal data, including Social Security Numbers (SSNs), affecting 4,892 individuals, among whom 10 were Maine residents. The breach exposed victims to potential identity theft risks, prompting the company to offer identity theft protection services as a remedial measure. The attack’s nature ransomware suggests malicious encryption of data, likely coupled with threats of exposure unless a ransom was paid. While the report does not specify whether the ransom was paid or if data was exfiltrated beyond SSNs, the involvement of highly sensitive identifiers elevates the severity. The breach underscores vulnerabilities in Cayan’s cybersecurity defenses, particularly against ransomware, which has increasingly targeted financial service providers and payment processors like Cayan to exploit valuable customer data.
TPRM report: https://www.rankiteo.com/company/cayanllc
"id": "cay1045092625",
"linkid": "cayanllc",
"type": "Ransomware",
"date": "10/2020",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'customers_affected': 4892,
'industry': 'Payment Processing / Financial Services',
'name': 'Cayan, LLC',
'type': 'Private Company'}],
'customer_advisories': ['Identity theft protection services offered to '
'affected individuals'],
'data_breach': {'number_of_records_exposed': 4892,
'personally_identifiable_information': ['Social Security '
'Numbers'],
'sensitivity_of_data': 'High (Social Security Numbers)',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)']},
'date_publicly_disclosed': '2021-07-13',
'description': 'The Maine Office of the Attorney General reported a data '
'breach affecting Cayan, LLC due to a ransomware attack. The '
'breach occurred between October 29, 2020, and November 18, '
'2020, compromising sensitive personal information, including '
'Social Security Numbers. Identity theft protection services '
'were offered to affected individuals.',
'impact': {'data_compromised': ['Social Security Numbers'],
'identity_theft_risk': 'High (identity theft protection services '
'offered)'},
'references': [{'date_accessed': '2021-07-13',
'source': 'Maine Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': ['Maine Office of the '
'Attorney General']},
'response': {'remediation_measures': ['Offered identity theft protection '
'services to affected individuals']},
'title': 'Cayan, LLC Ransomware Attack and Data Breach (2020)',
'type': ['ransomware', 'data breach']}