Social EngineeringPhishingMisdeliveryEmployee Data InvolvedData ExfiltratedTargetedPIIIDENTITY_GOVERNMENTEMPLOYMENTMediumContained
Colaberry, Inc.
bd_3f32ab8db6cf9bdd · schema v1 · pii pii-v1
Full breach record for Colaberry, Inc. →On February 6, 2026, Colaberry, Inc. discovered that a file containing 2025 Form W-2s for current and former employees had been inadvertently sent to an unauthorized external actor in response to a spoofed phishing email. Information involved included names, Social Security numbers, and other W-2 data. One Maine resident was affected. Colaberry notified the IRS, reviewed security policies, and offered 24-month credit monitoring via Cyberscout/TransUnion.
Maine clockDiscovered Feb 6, 2026 → Filed with AG Mar 24, 202646d ⏱ ME AG >30d7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_1cf10b11d5ea9491Indiana State AGfiled 2026-03-24Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/1bc4a467-c794-4ecc-96da-c5e8e4949010.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 24, 2026
- Raw hash
- cffc010e808576a653d67a497e11626b597393835bd7ed85268da34d87179935
Reporting entity
- Name
- Colaberry, Inc.norm: colaberry
- Domain
- colaberry.com
- Industry
- Other Commercial
Victim entity
- Name
- Colaberry, Inc.norm: colaberry
- Domain
- colaberry.com
- Industry
- Other Commercial
Incident
- Discovered
- Feb 6, 2026
- Materiality determined
- —
- Notification sent
- Mar 24, 2026
- Affected individuals
- 1
- Data types
- PIIIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maine Attorney GeneralNotified IRS of the incident
- Initial access
- phishing_attachment
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- ME AG >30d · 46d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 6, 2026→ Filed with AG: Mar 24, 202646d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.