Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICLowContained
County of Cumberland
bd_4c81f48289759c9d · schema v1 · pii pii-v1
Full breach record for County of Cumberland →On October 4, 2023, the County of Cumberland discovered unauthorized access to an employee's email account, likely via phishing. The incident affected one New Hampshire resident. The County engaged forensic specialists, provided credit monitoring via Experian, and notified the NH Attorney General on February 14, 2024.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_c1fa7c4f8ccf36afMaine State AGfiled 2024-02-14Candidate
- bd_ffe1a6097949e630Indiana State AGfiled 2024-02-14Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/county-cumberland-pennsylvania-20240214.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 14, 2024
- Raw hash
- 016d20f74e77107a888efabc56d23d9ba91190b7d3ebcb8e53b9e905f8a2fc99
Reporting entity
- Name
- County of Cumberlandnorm: county of cumberland
- Domain
- cumberlandcountypa.gov
Victim entity
- Name
- County of Cumberlandnorm: county of cumberland
- Domain
- cumberlandcountypa.gov
Incident
- Discovered
- Oct 4, 2023
- Materiality determined
- Jan 9, 2024
- Notification sent
- Feb 14, 2024
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- providing written notice of this incident to relevant state regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 19 weeks(133 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.