Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Cornerstone Benefits, Inc.
bd_3ad9f34c042a8284 · schema v1 · pii pii-v1
Full breach record for Cornerstone Benefits, Inc. →Cornerstone Benefits, Inc. notified the New Hampshire Attorney General of a data security incident involving unauthorized remote access to an employee's email account. The breach potentially exposed personal information, including names, addresses, Social Security numbers, and financial account details, of two New Hampshire residents. Notifications were mailed on October 18, 2019, offering one year of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_77b5bd0bd46e937bMontana State AGfiled 2019-10-21Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cornerstone-benefits-20191021.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 21, 2019
- Raw hash
- 89d56faf403d278d4b6d80caa0c225e01e054436b682ba117304d9f61157f9e4
Reporting entity
- Name
- Polsinelli PCnorm: polsinelli
Victim entity
- Name
- Cornerstone Benefits, Inc.norm: cornerstone benefits
Incident
- Discovered
- Jul 23, 2019
- Materiality determined
- —
- Notification sent
- Oct 18, 2019
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 13 weeks(90 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.