Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
USA Swimming, Inc.
bd_16e777965f1aa2fe · schema v1 · pii pii-v1
Full breach record for USA Swimming, Inc. →USA Swimming, Inc. notified the New Hampshire Attorney General of a data security incident affecting one NH resident. On June 30, 2021, USA Swimming detected unauthorized access to employee email accounts, likely via phishing. The attacker accessed personal information including name and passport number. USA Swimming engaged forensic investigators and notified the FBI. Notification to the affected individual occurred on September 17, 2021.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/usa-swimming-20210923.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 23, 2021
- Raw hash
- ac9fbecb22364a84e8d3d9104d412c205182689f5011f97b0eecb71c424539cd
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- USA Swimming, Inc.norm: usa swimming
Incident
- Discovered
- Jun 30, 2021
- Materiality determined
- —
- Notification sent
- Sep 17, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Federal Bureau of Investigation is aware of this incident
- Initial access
- phishing_link
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.