HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
The City of Osceola, Iowa
bd_3e9699d3712470e1 · schema v1 · pii pii-v1
Full breach record for The City of Osceola, Iowa →City of Osceola, Iowa notified the New Hampshire Attorney General of a security incident involving one NH resident. An unauthorized individual accessed a single employee email account between Feb 24 and Mar 17, 2021. The City determined on May 11, 2021, that the resident's name and Social Security number were accessed. The City secured the account, engaged a cybersecurity firm, and provided one year of Kroll credit monitoring services to the affected individual. Notification letters began mailing on June 3, 2021.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/city-osceola-iowa-20210603.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 3, 2021
- Raw hash
- 33480a2772e6d7af956018f15e23b09b1a8f901f07aceeb0d60f8a7434c872ef
Reporting entity
- Name
- The City of Osceola, Iowanorm: the city of osceola iowa
- Domain
- osceolaia.net
Victim entity
- Name
- The City of Osceola, Iowanorm: the city of osceola iowa
- Domain
- osceolaia.net
Incident
- Discovered
- Feb 24, 2021
- Materiality determined
- —
- Notification sent
- Jun 3, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(99 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.