Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICLowContained
D'Alberto Graham & Grimsley
bd_172240309112d0c5 · schema v1 · pii pii-v1
Full breach record for D'Alberto Graham & Grimsley →D’Alberto Graham & Grimsley notified the NH AG of an email account compromise. Unauthorized access occurred between July 8 and Dec 30, 2024. The firm detected unusual activity on Dec 27, 2024, engaged forensic specialists, and confirmed limited PII for one NH resident was affected. Notices and credit monitoring were sent in April 2025.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8f73d9f03c9bc0f6Indiana State AGfiled 2025-04-23Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/d-alberto-graham-grimsley-20250423.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2025
- Raw hash
- cf2a99adf6f9a789e46893ca931f3c043eae1d512a79c61930ed3ae08633375f
Reporting entity
- Name
- D'Alberto Graham & Grimsleynorm: d alberto graham grimsley
Victim entity
- Name
- D'Alberto Graham & Grimsleynorm: d alberto graham grimsley
Incident
- Discovered
- Dec 27, 2024
- Materiality determined
- Mar 10, 2025
- Notification sent
- Apr 23, 2025
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General Consumer Protection Bureau
- Initial access
- phishing_link
Compliance
- Time to disclose
- 17 weeks(117 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.