Social EngineeringPhishingCustomer Data InvolvedEmployee Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Chester County, Pennsylvania
bd_09bc89854cfe476d · schema v1 · pii pii-v1
Full breach record for Chester County, Pennsylvania →Chester County, Pennsylvania, notified the New Hampshire Attorney General of a phishing incident affecting five county employee email accounts. Unauthorized access occurred between August 3 and September 5, 2019. The breach exposed names, Social Security numbers, and driver's license numbers of one New Hampshire resident. The County disabled accounts, reset passwords, and offered one year of identity theft protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed5 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/chester-county-pennsylvania-20192011.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2019
- Raw hash
- 7a5ae29468f853ddd047a25153f39c1331e4fe3e2f20924ff32151130ba353fa
Reporting entity
- Name
- Chester County, Pennsylvanianorm: chester county pennsylvania
Victim entity
- Name
- Chester County, Pennsylvanianorm: chester county pennsylvania
Incident
- Discovered
- Aug 29, 2019
- Materiality determined
- —
- Notification sent
- Nov 13, 2019
- Affected individuals
- 5
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Consumer Protection Bureau
- Initial access
- phishing_link
Compliance
- Time to disclose
- 12 weeks(83 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.