HackingIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICMediumContained
Tom Wood Inc.
bd_4a3e4be0cb626e1b · schema v1 · pii pii-v1
Full breach record for Tom Wood Inc. →Tom Wood Group, an Indianapolis-based car dealership operator, notified the New Hampshire Attorney General of a security incident affecting one NH resident. Unauthorized access occurred between Sept 1-15, 2021; discovered Sept 11, 2021. The incident exposed name, SSN, driver's license, and limited medical info. TWG engaged a cybersecurity firm, reset passwords, and offered one year of Kroll credit monitoring to the affected individual.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_066c9cb9f24ac805Montana State AGfiled 2021-12-07(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/tom-wood-20211207.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 6, 2021
- Raw hash
- 851a8f2fd3db961396084e80f4b33464453b144d461f840016836c6532f5e36e
Reporting entity
- Name
- Tom Wood Inc.norm: tom wood
Victim entity
- Name
- Tom Wood Inc.norm: tom wood
Incident
- Discovered
- Sep 11, 2021
- Materiality determined
- —
- Notification sent
- Dec 7, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.