MisusePrivilege AbuseData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Lehigh Hanson, Inc.
bd_2c3f2abc6708c53a · schema v1 · pii pii-v1
Full breach record for Lehigh Hanson, Inc. →Lehigh Hanson, Inc. notified the New Hampshire Attorney General on December 8, 2008, regarding a security breach involving a former employee. The employee downloaded payroll data containing names and Social Security Numbers to a public university server. Two New Hampshire residents were affected. The data was removed, and forensic investigations confirmed no evidence of third-party access.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lehigh-hanson-20081208.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 8, 2008
- Raw hash
- 1def7c4b563966be1d9a85780ed238142e1e08624e8c21270a3089f6fdee4f47
Reporting entity
- Name
- Lehigh Hanson, Inc.norm: lehigh hanson
- Domain
- hanson.com
Victim entity
- Name
- Lehigh Hanson, Inc.norm: lehigh hanson
- Domain
- hanson.com
Incident
- Discovered
- Sep 1, 2008
- Materiality determined
- —
- Notification sent
- Dec 8, 2008
- Affected individuals
- 2
- Data types
- PIIIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- insider_action
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.