Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedTargetedPIIIDENTITY_GOVERNMENTMediumActive
BERG
bd_1efeb124afd9174a · schema v1 · pii pii-v1
Full breach record for BERG →Berg LLC, a Boston-based biopharma company, notified the NH Attorney General on March 21, 2017, of a breach affecting 186 employees. On or about Feb 1, 2017, an unknown actor impersonated the CEO via phishing to fraudulently obtain W-2 information. The breach involves one NH resident. Berg retained legal counsel and notified the FBI.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed186 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/berg-20170321.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 21, 2017
- Raw hash
- f0f5fe45f7d2c2a6a219f928f289261690de9898bfbee22a6a96bfea0cf606cc
Reporting entity
- Name
- MCCARTER & ENGLISH, LLPnorm: mccarter english
Victim entity
- Name
- BERGnorm: berg
- Domain
- berg.com
Incident
- Discovered
- Mar 16, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 186
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified FBI
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 days(5 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.