Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENTMediumContained
The J.N. Phillips Company, Inc.
bd_083507a2a2eb98ac · schema v1 · pii pii-v1
Full breach record for The J.N. Phillips Company, Inc. →The J.N. Phillips Company, Inc. reported a phishing incident to the New Hampshire Attorney General on March 17, 2017. An unauthorized actor impersonated management via email on February 16, 2017, tricking an employee into disclosing personal information of 24 New Hampshire residents. Data included names, addresses, SSNs, and W-2 details. The company provided 24 months of credit monitoring and notified affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed24 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/jn-phillips-20170317.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 17, 2017
- Raw hash
- 81780abc7b68d8ed79b897486bd45adac308375ce3088ac9ce528bbc86c4e9f6
Reporting entity
- Name
- The J.N. Phillips Company, Inc.norm: the jn phillips
Victim entity
- Name
- The J.N. Phillips Company, Inc.norm: the jn phillips
Incident
- Discovered
- Mar 7, 2017
- Materiality determined
- —
- Notification sent
- Mar 20, 2017
- Affected individuals
- 24
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Reporting of Security Incident Pursuant to N.H. Rev. Stat. § 359-C:20
- Initial access
- phishing_link
Compliance
- Time to disclose
- 10 days(10 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.