Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Metropolitan Council
bd_0970638fea8e9815 · schema v1 · pii pii-v1
Full breach record for Metropolitan Council →Metropolitan Council reported unauthorized access to employee email accounts between March 27 and May 27, 2024, following suspicious activity identified on April 12, 2024. The incident involved phishing leading to credential compromise. Potentially affected data included names, addresses, phone numbers, and SSNs. One New Hampshire resident was notified. Credit monitoring was offered.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1ef46e82b66a511fMontana State AGfiled 2024-12-04Candidate
- bd_7e63071c71169977Indiana State AGfiled 2024-12-03(1d gap)Verified
- bd_74e62c065020c672Maine State AGfiled 2024-12-06(2d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/metropolitan-council-20241204.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 4, 2024
- Raw hash
- 8e38f802b3169ec790ab20b06fc6abc9da917360ef6e70c30bac5b617b6f9c5e
Reporting entity
- Name
- Metropolitan Councilnorm: metropolitan council
Victim entity
- Name
- Metropolitan Councilnorm: metropolitan council
Incident
- Discovered
- Apr 12, 2024
- Materiality determined
- —
- Notification sent
- Nov 13, 2024
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- reporting this event to appropriate regulatorsproviding written notice of this event to appropriate state privacy regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 34 weeks(236 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.