Pathpoint analytics-tool data incident

Pathpoint discovered unauthorized database access through an internal analytics tool.

Last modified

Summary

  • Environment: Internal analytics tool and connected databases
  • Operational impact: Pathpoint reported no service interruption
  • Financial impact: No incident cost established in the reviewed evidence
  • Record status: Developing record. Reviewed October 7, 2026; updated as evidence emerges.

What happened

Pathpoint discovered unauthorized database access through an internal analytics tool. [1]

Impact

Accessed records included contact, policy, communications and billing information, plus some Social Security and tax identifiers. [1]

Timeline

  1. Discovery and containment

    Pathpoint identified and contained the incident.

    [1]
  2. Public notice

    Pathpoint published its incident notice.

    [1]
  3. Briefing updated

    This briefing was last reviewed and updated on October 7, 2026.

Threat Group & Attack Vector

Pathpoint attributed access to a previously unknown third-party software flaw; downloading remained possible rather than confirmed. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

It patched the tool, rotated credentials and restored a clean backup. [1]

Pathpoint reported uninterrupted services and offered affected individuals identity protection. [1]