Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICLowContained
PREMIUM MORTGAGE CORPORATION
bd_37ed9cb3d5d96909 · schema v1 · pii pii-v1
Full breach record for PREMIUM MORTGAGE CORPORATION →Premium Mortgage Corporation notified New Hampshire residents of a data breach involving unauthorized access to business email accounts between August 24 and 31, 2023. The incident was discovered on August 31, 2023, following suspicious activity. The breach likely resulted from phishing, leading to credential compromise. Affected data included names and other personal information. PMC notified law enforcement, engaged forensic specialists, and offered credit monitoring services to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_190ca9a5b7d55734Montana State AGfiled 2024-01-10Candidate
- bd_70ffa848cb0d4c34Maine State AGfiled 2024-01-10Candidate
- bd_fd46dfa8616fe5feIndiana State AGfiled 2024-01-10Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/premium-mortgage-corporation-20240110.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 10, 2024
- Raw hash
- 6bd81241616d78e36275065aeac1b1f2871241fcbe296c5338850c30e8dc7227
Reporting entity
- Name
- PREMIUM MORTGAGE CORPORATIONnorm: premium mortgage
Victim entity
- Name
- PREMIUM MORTGAGE CORPORATIONnorm: premium mortgage
Incident
- Discovered
- Aug 31, 2023
- Materiality determined
- Nov 29, 2023
- Notification sent
- Jan 10, 2024
- Affected individuals
- 9
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- notified federal law enforcement regarding the incidentproviding written notice of this incident to relevant state regulators, as necessary, and to the three major credit reporting agencies, Equifax, Experian, and TransUnion
- Initial access
- phishing_link
Compliance
- Time to disclose
- 19 weeks(132 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.