Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
SourceOne
bd_24d77a61ecaf9bc0 · schema v1 · pii pii-v1
Full breach record for SourceOne →SourceOne Insurance Group notified the NH AG of a phishing incident affecting one NH resident. Unauthorized access to employee email accounts occurred between April 20 and May 11, 2021. The attacker accessed a resident's name and SSN. SourceOne reset passwords, engaged forensic investigators, and reported to the FBI. One resident was notified on August 30, 2021, and offered credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sourceone-insurance-20210830.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 30, 2021
- Raw hash
- a1fc44b280b7360534dffdcd37464cc2a88c1daee3b9e14033599edc570f164e
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- SourceOnenorm: sourceone
- Domain
- sourceone.global
Incident
- Discovered
- May 11, 2021
- Materiality determined
- —
- Notification sent
- Aug 30, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- phishing_link
Compliance
- Time to disclose
- 16 weeks(111 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.