DisclosureLens
Social EngineeringHospitalityHospitalityPhishingCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDFinancialMediumActive

InterMountain Management

bd_3a93eefaf231e791 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 6, 2017

Filed

Feb 22, 2017

To disclose

16 days

Affected

558state residents only

Linked

4 filings

Confidence

69%
Full breach record for InterMountain Management

InterMountain Management, LLC reported an email spoofing attack on Feb 3, 2017, where an attacker impersonated the owner to request 2016 W-2 forms. The company disclosed the incident on Feb 6, 2017, and began notifying 558 Washington residents on Feb 21, 2017. Affected data included names, addresses, SSNs, and wage info. The company provided 2 years of credit monitoring and notified the IRS.

Incident timeline

undetected · 3 days
discovery → filing · 16 days

Feb 3, 2017

Begins

Feb 6, 2017

Discovered

Feb 22, 2017

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
New Hampshire State AGFeb 22 · first
Montana State AGFeb 22 · first
Massachusetts State AGFeb 22 · first
Washington State AGFeb 22 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.