Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedTargetedPIIIDENTITY_BASICLowContained
Heartland Bank
bd_16d76fb514a53547 · schema v1 · pii pii-v1
Full breach record for Heartland Bank →Heartland Bank notified the New Hampshire Attorney General of a cybersecurity incident involving one NH resident. Unauthorized access to employee email accounts occurred between Oct 31 and Nov 9, 2024. The bank secured accounts, investigated, and mailed notification on Feb 7, 2025. Personal information was found in the accessed emails. The bank is enhancing email security.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0eb78e39a1ffe3d9Maryland State AGfiled 2025-02-07Verified
- bd_35a2394732e77a6eMontana State AGfiled 2025-02-07Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/heartland-bank-20250207.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 7, 2025
- Raw hash
- 8d1298684cd06391ba1d814bec7fbc05132c3cab2b5e66e097770710e2b0a2a5
Reporting entity
- Name
- Heartland Banknorm: heartland bank
Victim entity
- Name
- Heartland Banknorm: heartland bank
Incident
- Discovered
- Nov 9, 2024
- Materiality determined
- Jan 9, 2025
- Notification sent
- Feb 7, 2025
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- phishing_link
Compliance
- Time to disclose
- 13 weeks(90 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.