Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIALMediumActive
MAXIM CRANE WORKS, L.P.
bd_1bc2313cbed38000 · schema v1 · pii pii-v1
Full breach record for MAXIM CRANE WORKS, L.P. →Maxim Crane Works, L.P. notified the New Hampshire Attorney General on March 15, 2017, regarding a phishing incident where W-2 forms of employees were sent to an unauthorized external email address. The breach affected 10 New Hampshire residents, exposing names, addresses, income info, and SSNs. The company reported to the FBI and IRS, notified credit bureaus, and offered 24 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/maxim-crane-20170315.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 15, 2017
- Raw hash
- 23d57da4ca6b95477b5193f9de4adc0cb08fe97c30a5d994f7fa537bcf7cf924
Reporting entity
- Name
- CLARK HILL PLCnorm: clark hill
Victim entity
- Name
- MAXIM CRANE WORKS, L.P.norm: maxim crane works
Incident
- Discovered
- Feb 22, 2017
- Materiality determined
- —
- Notification sent
- Mar 1, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.