Kahua Announces Data Breach Following Ransomware Attack | Console and Associates, P.C.


On December 15, 2023, Kahua filed a notice of data breach with the Attorney General of Vermont after discovering that the company had fallen victim to a ransomware attack. In this notice, Kahua explains that the incident resulted in an unauthorized party being able to access consumers’ sensitive information. Upon completing its investigation, Kahua began sending out data breach notification letters to all individuals whose information was affected by the recent data security incident.

If you received a data breach notification from Kahua, it is essential you understand what is at risk and what you can do about it. A data breach lawyer can help you learn more about how to protect yourself from becoming a victim of fraud or identity theft, as well as discuss your legal options following the Kahua data breach. For more information, please see our recent piece on the topic here.

What Caused the Kahua Data Breach?

The Kahua data breach was only recently announced, and more information is expected in the near future. However, Kahua’s filing with the Attorney General of Vermont provides some important information on what led up to the breach. According to this source, on November 13, 2023, Kahua received a ransomware note in an email. Noting that the company’s IT systems were not encrypted, Kahua started working with outside data security professionals to investigate the incident.

The Kahua investigation ultimately determined that an unauthorized party was able to access the company’s computer network between October 25, 2023 and November 13, 2023. It was also confirmed that some of the files that were accessible to the unauthorized party contained confidential consumer information.

After learning that sensitive consumer data was accessible to an unauthorized party, Kahua reviewed the compromised files to determine what information was leaked and which consumers were impacted.

On December 15, 2023, Kahua sent out data breach letters to anyone who was affected by the recent data security incident. Unfortunately, the publicly available data breach letter from Kahua does not list what type of information was subject to unauthorized access. However, the personalized data…

Source…