Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Eagle Bank
bd_44f0f9aa93d5b4f3 · schema v1 · pii pii-v1
Full breach record for Eagle Bank →Eagle Bank notified the New Hampshire Attorney General of a data breach affecting 5 NH residents. On July 30, 2022, an employee email account was compromised via a phishing email sent on September 20, 2022. The attacker accessed files containing SSNs, driver's license numbers, financial account numbers, and dates of birth. Eagle Bank engaged forensic experts, notified law enforcement, and offered two years of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5675ceaf3f5ef5b3Maine State AGfiled 2022-11-08(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/eagle-bank-20221107.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 7, 2022
- Raw hash
- 28fdc4182461e864c4a54a76610a390c398d1faf1d5308fcd2772991a446065f
Reporting entity
- Name
- Eagle Banknorm: eagle bank
Victim entity
- Name
- Eagle Banknorm: eagle bank
Incident
- Discovered
- Sep 20, 2022
- Materiality determined
- —
- Notification sent
- Nov 8, 2022
- Affected individuals
- 5
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the Attorney General, Consumer Protection and Antitrust Bureau
- Initial access
- phishing_link
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.