Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
GOODWIN PROCTER LLP
bd_169c974ce853c148 · schema v1 · pii pii-v1
Full breach record for GOODWIN PROCTER LLP →Goodwin Procter LLP reported a cybersecurity incident to the New Hampshire Attorney General on June 22, 2026. On April 16, 2026, a single user account was compromised via social engineering (phishing). The attacker accessed the network for a limited period, obtaining personal information of one New Hampshire resident, including name, address, SSN, and financial account/credit card numbers. Goodwin disabled the account, engaged third-party experts, notified law enforcement, and offered two years of credit monitoring. The incident is contained.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_4cb0a53fd8c5954cIndiana State AGfiled 2026-06-11(11d gap)Candidate
- bd_e606468cb7b5688aTexas State AGfiled 2026-07-31(39d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/goodwin-procter-20260622.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 22, 2026
- Raw hash
- 4e3b1ba57746a7a15069a268ab1878508484882d59982b501b1075fd8e699f47
Reporting entity
- Name
- GOODWIN PROCTER LLPnorm: goodwin procter
- Domain
- goodwinlaw.com
- Industry
- Legal Services
Victim entity
- Name
- GOODWIN PROCTER LLPnorm: goodwin procter
- Domain
- goodwinlaw.com
- Industry
- Legal Services
Incident
- Discovered
- Apr 16, 2026
- Materiality determined
- —
- Notification sent
- Jun 11, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Consumer Protection Bureau
- Initial access
- phishing_link
Compliance
- Time to disclose
- 10 weeks(67 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.