Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Sumter County, GA Official Website
bd_3f3dbb06d93e736d · schema v1 · pii pii-v1
Full breach record for Sumter County, GA Official Website →Sumter County, SC, notified individuals of a phishing incident where an employee email account was compromised. Attackers accessed email contents, potentially exposing names, addresses, DOBs, and SSNs/driver's license numbers of employees, vendors, and applicants. The county reset passwords, disabled the account, engaged cybersecurity experts, and offered 12 months of Experian IdentityWorks.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2021/SumterCounty.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 2, 2021
- Raw hash
- 5e6960447d1b9ed33486eda7107a55cbf7207239258ac68ad10effa7e3c72d0f
Reporting entity
- Name
- Sumter County, GA Official Websitenorm: sumter county ga official website
- Domain
- sumtercountyga.us
Victim entity
- Name
- Sumter County, GA Official Websitenorm: sumter county ga official website
- Domain
- sumtercountyga.us
Incident
- Discovered
- Sep 1, 2021
- Materiality determined
- —
- Notification sent
- Nov 1, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.