Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
KuberneoCPA
bd_3f951fc4a9886e45 · schema v1 · pii pii-v1
Full breach record for KuberneoCPA →KuberneoCPA notified the NH Attorney General of a phishing incident affecting 3 NH residents. Unauthorized access to employee email accounts occurred March 31–April 25, 2020. Discovery was December 10, 2020. Names and SSNs were accessed. No evidence of misuse. 12 months credit monitoring provided.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/kuberneocpa-20210114.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 14, 2021
- Raw hash
- 064351fece14a2b03ae5f36a27d7dcc9334f35a2391c39019901dc42553010c3
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- KuberneoCPAnorm: kuberneocpa
Incident
- Discovered
- Dec 10, 2020
- Materiality determined
- —
- Notification sent
- Dec 21, 2020
- Affected individuals
- 3
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.