HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedFINANCIAL_ACCOUNTIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Goodwill Industries of the Southern Piedmont, Inc.
bd_02ccb65d22ef5a0b · schema v1 · pii pii-v1
Full breach record for Goodwill Industries of the Southern Piedmont, Inc. →Goodwill Industries of the Southern Piedmont reported unauthorized network access on May 11, 2022. The incident affected personal information including financial account data, driver's licenses, and SSNs. Seven New Hampshire residents were notified on March 24, 2023. Goodwill engaged cybersecurity experts, secured the network, and offered credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3836f5bc85249ac4Montana State AGfiled 2023-03-24Candidate
- bd_53d68717d43017cfMaine State AGfiled 2023-03-24Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/goodwill-industries-southern-piedmont-20230324.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 24, 2023
- Raw hash
- ab15eb0c3d420bb92af3db92f8226ffcb6d85fac9c4ee26070817924b05c16c0
Reporting entity
- Name
- Goodwill Industries of the Southern Piedmont, Inc.norm: goodwill industries of the southern piedmont
Victim entity
- Name
- Goodwill Industries of the Southern Piedmont, Inc.norm: goodwill industries of the southern piedmont
Incident
- Discovered
- May 11, 2022
- Materiality determined
- Mar 20, 2023
- Notification sent
- Mar 24, 2023
- Affected individuals
- 7
- Data types
- FINANCIAL_ACCOUNTIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 45 weeks(317 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.