Social EngineeringPhishingCustomer Data InvolvedTargetedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Great Lakes Wellness
bd_3a0410a5817d65d9 · schema v1 · pii pii-v1
Full breach record for Great Lakes Wellness →Great Lakes Gelatin Company, LLC notified the New Hampshire Attorney General of a security incident involving unauthorized access to two employees' email accounts. The unauthorized access occurred between October 13, 2020, and November 3, 2020. The investigation determined that an email or attachment contained the name and Social Security number of one New Hampshire resident. The actor's motive was financial (attempted wire fraud), not data theft. The company secured accounts, engaged an outside IT firm, and offered one year of credit monitoring to the affected resident.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/great-lakes-gelatin-20210302.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 2, 2021
- Raw hash
- 2bc068227b771764b8e10ee9117995d5f5139ae359ea6617ac75ee158e9eeb19
Reporting entity
- Name
- Great Lakes Gelatin Company, LLCnorm: great lakes gelatin
Victim entity
- Name
- Great Lakes Wellnessnorm: great lakes wellness
- Domain
- greatlakeswellness.com
Incident
- Discovered
- Feb 4, 2021
- Materiality determined
- —
- Notification sent
- Mar 1, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 26 days(26 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.