Social EngineeringPhishingStolen CredentialsBECMulti-Stage ChainWire FraudCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
PHILLIP CAPITAL INC.
bd_3abf8cbfa0eaae98 · schema v1 · pii pii-v1
Full breach record for PHILLIP CAPITAL INC. →Phillip Capital Inc. disclosed a cyber-hacking incident on February 28, 2018, initiated by a phishing email from a third-party vendor. Attackers accessed employee email accounts to identify corporate clients for wire fraud. Compromised data included names, addresses, SSNs, and banking information. The company contained the breach, cooperated with law enforcement, and offered 12 months of identity monitoring to affected customers.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_bd0639fb78687f1cMontana State AGfiled 2019-02-21(7d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-145084
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 28, 2019
- Raw hash
- 1f3f5e9c7d9616fe131f6fe63ce1c8cab6f1fcf2c2dfeb64e005c6d19d2f024d
Reporting entity
- Name
- PHILLIP CAPITAL INC.norm: phillip capital
- Domain
- phillipcapital.com
Victim entity
- Name
- PHILLIP CAPITAL INC.norm: phillip capital
- Domain
- phillipcapital.com
Incident
- Discovered
- Feb 28, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 12 months(365 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.