Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
Grandizio Wilkins Little & Matthews, LLP
bd_35b3a7fba97c5d33 · schema v1 · pii pii-v1
Full breach record for Grandizio Wilkins Little & Matthews, LLP →Grandizio Wilkins Little & Matthews, LLP disclosed a data security incident involving unauthorized access to an employee's email account. The breach, discovered on June 7, 2021, potentially exposed personal information including names, SSNs, medical info, driver's license info, and financial/payment card data. GWLM engaged cybersecurity experts and IDX for credit monitoring services, notifying affected individuals in January 2022.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_628b4a53f2a6ffd7Maine State AGfiled 2022-01-14Verified by operator
- bd_68e41a6065c14fc1New Hampshire State AGfiled 2022-01-14Verified
- bd_2912bfae25457784Delaware State AGfiled 2021-12-17(28d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/02/Pages-from-GWLM-Regulatory-Notification-Letter-DE-Packet.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 14, 2022
- Raw hash
- 9ddf020fb408f5f014d4d0643bbb709f3049baafd3d8e21c614d49a7510c7fef
Reporting entity
- Name
- Grandizio Wilkins Little & Matthews, LLPnorm: grandizio wilkins little matthews
Victim entity
- Name
- Grandizio Wilkins Little & Matthews, LLPnorm: grandizio wilkins little matthews
Incident
- Discovered
- Jun 7, 2021
- Materiality determined
- —
- Notification sent
- Jan 14, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 32 weeks(221 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.