CANTELLA & CO.,INC.
bd_47cef584df20f319 · schema v1 · pii pii-v1
Full breach record for CANTELLA & CO.,INC. →Cantella & Co., Inc. reported a cybersecurity incident to the New Hampshire Department of Justice on November 16, 2020, regarding an Emotet malware infection detected on August 25, 2020. The incident involved phishing emails with malicious .doc attachments that infected 23 computers (10 home office, 13 advisors). The malware exfiltrated email strings and potentially client PII (names, addresses, SSNs) and credentials. Cantella notified clients, offered two years of credit monitoring via Experian, and engaged external forensic partners. All infected machines were wiped and rebuilt, and passwords were reset.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 25, 2020
Begins
Aug 25, 2020
Discovered
Nov 17, 2020
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_041fe2fc8d4fcade2020-11-11 · +6dVerified
- California State AGbd_386705a1849002e72020-11-10 · +7dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Nov 10 (CA), last Nov 17 (NH) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.